PT-2017-11804 · Rise · Rise Ultimate Project Manager
Published
2017-07-12
·
Updated
2017-07-14
·
CVE-2017-11182
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Rise Ultimate Project Manager version 1.8
Description
A security issue was discovered in the My Profile section, where all input fields are susceptible to XSS attacks.
Recommendations
For version 1.8, ensure proper input validation and sanitization to prevent XSS attacks in the My Profile section. Consider temporarily restricting access to this section until a fix is implemented.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rise Ultimate Project Manager