PT-2023-10104 · Unknown · Stiiv Contact App

CVE-2014-125034

·

Publicado

2023-01-02

·

Atualizado

2024-05-17

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions stiiv contact app (affected versions not specified)
Description A vulnerability has been found in stiiv contact app and classified as problematic. The function render of the file libs/View.php is affected by this issue. The manipulation of the argument var leads to cross site scripting. The attack can be launched remotely.
Recommendations To fix this issue, it is recommended to apply a patch named 67bec33f559da9d41a1b45eb9e992bd8683a7f8c. As a temporary workaround, consider disabling the render function of the libs/View.php file until the patch is applied. Restrict access to the var argument to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-125034

Produtos afetados

Stiiv Contact App