PT-2019-9840 · Webgalamb · Webgalamb
Daniel Jones
·
Publicado
2019-03-17
·
Atualizado
2019-03-21
·
CVE-2018-19509
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Webgalamb version 7.0
Description
The issue arises from the wg7.php file in Webgalamb, which makes opportunistic calls to
htmlspecialchars() instead of utilizing a templating engine with proper contextual encoding. This allows for the insertion of arbitrary strings into the database, enabling any JavaScript to be executed by the administrator, resulting in a cross-site scripting (XSS) issue.Recommendations
For Webgalamb version 7.0, consider implementing a templating engine with proper contextual encoding to mitigate the risk of XSS attacks. As a temporary workaround, restrict access to the wg7.php file and ensure that all user input is thoroughly validated and sanitized to prevent malicious string insertion.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Webgalamb