PT-2007-5057 · Citadel · Webcit

Published

2007-07-17

·

Updated

2018-10-15

·

CVE-2007-3822

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Webcit versions prior to 7.11
Description: The issue involves multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web script or HTML. The vulnerable parameters include the who parameter to showuser, as well as other vectors related to calendar mode, bulletin board mode, room names, and uploaded file names.
Recommendations: For versions prior to 7.11, update to version 7.11 or later to resolve the issue. As a temporary workaround, consider restricting user input for the who parameter and limiting access to calendar mode, bulletin board mode, and uploaded files until the update is applied. Avoid using potentially malicious room names and uploaded file names until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3822

Affected Products

Webcit