PT-2023-10253 · Openseamap · Openseamap Online Chart

Aaxee

·

Publicado

2023-02-07

·

Atualizado

2024-05-17

·

CVE-2015-10074

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenSeaMap online chart version 1.2
Description A vulnerability was found in the function init of the file index.php. The manipulation of the argument mtext leads to cross site scripting. It is possible to launch the attack remotely.
Recommendations For OpenSeaMap online chart version 1.2, upgrade to version staging to address this issue. As a temporary workaround, consider restricting access to the init function in the index.php file until the upgrade is applied. Additionally, avoid using the mtext argument in the affected component until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-10074

Produtos afetados

Openseamap Online Chart