PT-2014-8617 · Jexperts · Jexperts Channel Platform
Publicado
2014-11-13
·
Atualizado
2017-09-08
·
CVE-2014-8557
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
JExperts Channel Platform version 5.0.33 CCB
Description
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the
usuario.nome variable in an 'editarUsuario' action to 'usuario.do' or the titulo.form variable in a 'novoChamado' action to 'ticket.do'.Recommendations
For JExperts Channel Platform version 5.0.33 CCB, as a temporary workaround, consider restricting access to the 'usuario.do' and 'ticket.do' endpoints until a patch is available. Avoid using the
usuario.nome and titulo.form variables in the affected actions until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jexperts Channel Platform