PT-2023-29433 · Unknown · Change Request
Michitux
·
Publicado
2023-10-12
·
Atualizado
2023-10-18
·
CVE-2023-45138
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Change Request versions 0.11 through 1.9.2
Description
The issue allows a user without specific rights to perform script injection and remote code execution by inserting an appropriate title when creating a new Change Request. This is particularly critical as Change Request is intended for use by users without particular rights.
Recommendations
For versions prior to 1.9.2, upgrade to Change Request 1.9.2 to resolve the issue.
As a temporary workaround for versions prior to 1.9.2, edit the document
ChangeRequest.Code.ChangeRequestSheet and perform the same change as in the fix commit.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Change Request