PT-2017-13676 · Genix · Genixcms

Publicado

2017-09-27

·

Atualizado

2022-05-17

·

CVE-2017-14762

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GeniXCMS version 1.1.4
Description The issue is related to a Cross-Site Scripting (XSS) problem. Specifically, the /inc/lib/Control/Backend/menus.control.php endpoint is vulnerable to XSS via the id parameter. This means an attacker could potentially inject malicious scripts into the website, affecting users who interact with the vulnerable page.
Recommendations For GeniXCMS version 1.1.4, as a temporary workaround, consider restricting access to the /inc/lib/Control/Backend/menus.control.php endpoint or avoid using the id parameter in this context until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14762
GHSA-JGC6-JR94-H442

Produtos afetados

Genixcms