PT-2011-1836 · Mysource · Mysource Matrix

Gjoko Krstic

·

Published

2011-10-08

·

Updated

2013-01-04

·

CVE-2010-4901

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions MySource Matrix version 3.28.3
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML. The injection can occur via the height or width parameter in the char map.php file.
Recommendations For MySource Matrix version 3.28.3, consider restricting access to the char map.php file until a patch is available. As a temporary workaround, avoid using the height and width parameters in the char map.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4901

Affected Products

Mysource Matrix