PT-2014-9074 · Mayan · Mayan Edms

Published

2014-05-27

·

Updated

2014-05-27

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Mayan EDMS version 0.13
Description The issue allows remote authenticated users to inject arbitrary web script or HTML. This can be achieved via a tag or the title of a source in a Staging folder, the Name field in a bootstrap setup, or the Title field in a smart link or web form.
Recommendations For Mayan EDMS version 0.13, update to a version that fixes the cross-site scripting vulnerabilities. As a temporary workaround, consider restricting access to the calculate form title.html template and limiting user input in the affected fields, such as the title and Name fields, to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2014-110

Affected Products

Mayan Edms