PT-2019-9840 · Webgalamb · Webgalamb

Daniel Jones

·

Publicado

2019-03-17

·

Atualizado

2019-03-21

·

CVE-2018-19509

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Webgalamb version 7.0
Description The issue arises from the wg7.php file in Webgalamb, which makes opportunistic calls to htmlspecialchars() instead of utilizing a templating engine with proper contextual encoding. This allows for the insertion of arbitrary strings into the database, enabling any JavaScript to be executed by the administrator, resulting in a cross-site scripting (XSS) issue.
Recommendations For Webgalamb version 7.0, consider implementing a templating engine with proper contextual encoding to mitigate the risk of XSS attacks. As a temporary workaround, restrict access to the wg7.php file and ensure that all user input is thoroughly validated and sanitized to prevent malicious string insertion.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-19509

Produtos afetados

Webgalamb