PT-2008-1029 · Roundup · Roundup
Publicado
2008-03-24
·
Atualizado
2022-05-01
·
CVE-2008-1474
CVSS v4.0
5.3
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Roundup versions prior to 1.4.4
Description
The issue concerns multiple unspecified vulnerabilities in the Roundup package, which can be exploited remotely. These vulnerabilities may lead to a breach of protected information integrity. Some of the vulnerabilities might be related to cross-site scripting (XSS), which is a type of attack where an attacker injects malicious code into a website, allowing them to steal user data or take control of the user's session.
Recommendations
For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Roundup package to minimize the risk of exploitation. Avoid using the Roundup package for sensitive operations until the issue is resolved.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Roundup