PT-2017-13234 · Securimage · Securimage

Publicado

2017-11-18

·

Atualizado

2022-05-13

·

CVE-2017-14077

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Securimage versions 3.6.4 and earlier Securimage versions prior to 3.6.6
Description The issue allows remote attackers to inject arbitrary HTML into an e-mail message body via the HTTP USER AGENT parameter to "example form.ajax.php" or "example form.php" API endpoints.
Recommendations For Securimage versions 3.6.4 and earlier, update to version 3.6.6 or later to resolve the issue. For Securimage versions prior to 3.6.6, update to version 3.6.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the example form.ajax.php and example form.php API endpoints to minimize the risk of exploitation. Avoid using the HTTP USER AGENT parameter in the affected API endpoints until the issue is resolved.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14077
GHSA-Q6V4-XJP2-8GGV

Produtos afetados

Securimage