PT-2014-8617 · Jexperts · Jexperts Channel Platform
Published
2014-11-13
·
Updated
2017-09-08
·
CVE-2014-8557
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
JExperts Channel Platform version 5.0.33 CCB
Description
The issue allows remote attackers to inject arbitrary web script or HTML. This can be achieved via the
usuario.nome variable in an 'editarUsuario' action to 'usuario.do' or the titulo.form variable in a 'novoChamado' action to 'ticket.do'.Recommendations
For JExperts Channel Platform version 5.0.33 CCB, as a temporary workaround, consider restricting access to the 'usuario.do' and 'ticket.do' endpoints until a patch is available. Avoid using the
usuario.nome and titulo.form variables in the affected actions until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jexperts Channel Platform