PT-2011-2620 · Janrain · Janrain Engage
Publicado
2011-02-04
·
Atualizado
2017-08-17
·
CVE-2011-0771
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Janrain Engage module versions 6.x-1.3
Description
The issue allows remote authenticated users to conduct cross-site scripting (XSS) attacks and possibly execute arbitrary PHP code by causing a crafted avatar to be downloaded from an external login provider site, due to the lack of validation for profile image files.
Recommendations
For Janrain Engage module version 6.x-1.3, consider validating profile image files to prevent cross-site scripting (XSS) attacks and the possible execution of arbitrary PHP code. As a temporary workaround, restrict the ability to download avatars from external login provider sites until a proper fix is applied.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Janrain Engage