PT-2019-8869 · Clippercms · Clippercms
Prasadlingamaiah
·
Publicado
2019-08-15
·
Atualizado
2019-08-26
·
CVE-2018-12101
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CMS Clipper version 1.3.3
Description
The issue concerns a security problem where an attacker can inject malicious code. This is possible due to insufficient input validation in several fields, including the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.
Recommendations
For CMS Clipper version 1.3.3, update to a version that addresses this issue, as the current version allows for malicious code injection in the specified fields. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Clippercms