PT-2013-1951 · Silverstripe · Silverstripe Cms+1

Publicado

2013-08-09

·

Atualizado

2013-08-13

·

CVE-2012-6458

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SilverStripe e-commerce module version 3.0 for SilverStripe CMS
Description The issue allows remote attackers to inject arbitrary web script or HTML via specific parameters, including FirstName, Surname, and Email to "code/forms/OrderFormAddress.php", or FirstName and Surname to "code/forms/ShopAccountForm.php".
Recommendations For SilverStripe e-commerce module version 3.0, consider restricting the input for the FirstName, Surname, and Email parameters in "code/forms/OrderFormAddress.php" and the FirstName and Surname parameters in "code/forms/ShopAccountForm.php" to prevent arbitrary web script or HTML injection until a patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-6458

Produtos afetados

Silverstripe Cms
Silverstripe E-Commerce Module