PT-2010-3137 · Mono · Mono

Published

2010-05-27

·

Updated

2022-05-02

·

CVE-2010-1459

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mono versions prior to 2.6.4
Description The default configuration of ASP.NET in Mono has a value of FALSE for the EnableViewStateMac property, allowing remote attackers to conduct cross-site scripting (XSS) attacks. This is demonstrated by the VIEWSTATE parameter to "2.0/menu/menu1.aspx" in the XSP sample project.
Recommendations For Mono versions prior to 2.6.4, update to version 2.6.4 or later to resolve the issue. As a temporary workaround, consider setting the EnableViewStateMac property to TRUE to mitigate the risk of XSS attacks. Restrict access to the VIEWSTATE parameter in the affected API endpoint until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1459
GHSA-G5C6-W479-93XM

Affected Products

Mono