PT-2018-9571 · Freshdns · Freshdns
Luelistao
·
Publicado
2018-12-20
·
Atualizado
2019-01-08
·
CVE-2018-1000847
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FreshDNS versions 1.0.3 and prior
Description
The issue allows for the execution of an attacker's JavaScript code in a victim's session due to a Cross Site Scripting (XSS) vulnerability in the Account data form and Zone editor. This can be exploited when an attacker stores a specially crafted string as their Full Name in their account details, and the victim, such as the administrator, opens the User List in the admin interface.
Recommendations
For FreshDNS versions 1.0.3 and prior, update to version 1.0.5 or later to resolve the issue.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Freshdns