PT-2017-11803 · Rise · Rise Ultimate Project Manager
Published
2017-07-12
·
Updated
2017-07-14
·
CVE-2017-11181
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rise Ultimate Project Manager version 1.8
Description
The issue concerns XSS vulnerabilities found in the Messaging section of the software. Specifically, the
Subject and Message fields are vulnerable.Recommendations
For Rise Ultimate Project Manager version 1.8, consider disabling the Messaging section until a patch is available to prevent potential exploitation of the XSS vulnerabilities in the
Subject and Message fields.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rise Ultimate Project Manager