PT-2009-6018 · Opendocman · Opendocman

Publicado

2009-10-26

·

Atualizado

2017-08-17

·

CVE-2009-3789

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenDocMan version 1.2.5
Description The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved through various means, including the last message parameter to several API endpoints, such as "/add.php", "/toBePublished.php", "/index.php", and "/admin.php". Additionally, the PATH INFO to the default URI in endpoints like "/category.php", "/department.php", "/profile.php", "/rejects.php", "/search.php", "/toBePublished.php", "/user.php", and "/view file.php" can be exploited. The caller parameter in a Modify User action to "/user.php" is also vulnerable.
Recommendations For OpenDocMan version 1.2.5, consider disabling the last message parameter in the affected API endpoints until a patch is available. Restrict access to the vulnerable endpoints, such as "/category.php", "/department.php", "/profile.php", "/rejects.php", "/search.php", "/toBePublished.php", "/user.php", and "/view file.php", to minimize the risk of exploitation. Avoid using the caller parameter in the Modify User action to "/user.php" until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3789

Produtos afetados

Opendocman