PT-2008-1029 · Roundup · Roundup

Publicado

2008-03-24

·

Atualizado

2022-05-01

·

CVE-2008-1474

CVSS v4.0

5.3

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Roundup versions prior to 1.4.4
Description The issue concerns multiple unspecified vulnerabilities in the Roundup package, which can be exploited remotely. These vulnerabilities may lead to a breach of protected information integrity. Some of the vulnerabilities might be related to cross-site scripting (XSS), which is a type of attack where an attacker injects malicious code into a website, allowing them to steal user data or take control of the user's session.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Roundup package to minimize the risk of exploitation. Avoid using the Roundup package for sensitive operations until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02584
CVE-2008-1474
DSA-1554-1
GHSA-C3QV-MF8H-434R
PYSEC-2008-9

Produtos afetados

Roundup