PT-2018-9571 · Freshdns · Freshdns

Luelistao

·

Publicado

2018-12-20

·

Atualizado

2019-01-08

·

CVE-2018-1000847

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FreshDNS versions 1.0.3 and prior
Description The issue allows for the execution of an attacker's JavaScript code in a victim's session due to a Cross Site Scripting (XSS) vulnerability in the Account data form and Zone editor. This can be exploited when an attacker stores a specially crafted string as their Full Name in their account details, and the victim, such as the administrator, opens the User List in the admin interface.
Recommendations For FreshDNS versions 1.0.3 and prior, update to version 1.0.5 or later to resolve the issue.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-1000847

Produtos afetados

Freshdns