PT-2004-2866 · Openbb · Openbb

Jeiar

·

Published

2004-04-25

·

Updated

2017-07-11

·

CVE-2004-1969

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OpenBB versions 1.0.6 and earlier
Description The issue allows remote attackers to execute arbitrary script by uploading files that include scripting code, such as Javascript, through the avatar upload capability.
Recommendations For OpenBB versions 1.0.6 and earlier, consider disabling the avatar upload feature until a patch is available to prevent the execution of arbitrary scripts.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1969

Affected Products

Openbb