PT-2015-7290 · Opentext · Opentext Secure Mft

Alexander Stra�Heim

+1

·

Publicado

2015-08-20

·

Atualizado

2018-10-09

·

CVE-2015-6530

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenText Secure MFT versions 2013 before 2013 R3 P6 OpenText Secure MFT versions 2014 before 2014 R2 P2
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the querytext parameter to the "userdashboard.jsp" endpoint.
Recommendations For OpenText Secure MFT versions 2013 before 2013 R3 P6, update to version 2013 R3 P6 or later. For OpenText Secure MFT versions 2014 before 2014 R2 P2, update to version 2014 R2 P2 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6530

Produtos afetados

Opentext Secure Mft