PT-2007-5057 · Citadel · Webcit
Published
2007-07-17
·
Updated
2018-10-15
·
CVE-2007-3822
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Webcit versions prior to 7.11
Description:
The issue involves multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web script or HTML. The vulnerable parameters include the
who parameter to showuser, as well as other vectors related to calendar mode, bulletin board mode, room names, and uploaded file names.Recommendations:
For versions prior to 7.11, update to version 7.11 or later to resolve the issue. As a temporary workaround, consider restricting user input for the
who parameter and limiting access to calendar mode, bulletin board mode, and uploaded files until the update is applied. Avoid using potentially malicious room names and uploaded file names until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Webcit