PT-2017-17160 · Agora · Agora-Project

Published

2017-03-09

·

Updated

2019-03-19

·

CVE-2017-6562

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Agora-Project version 3.2.2
Description The issue is related to a cross-site scripting (XSS) attack. It affects the index.php file, specifically when the ctrl parameter is set to 'file', the targetObjId parameter is set to 'fileFolder-2', and the targetObjIdChild parameter contains malicious input, allowing for an XSS attack.
Recommendations For Agora-Project version 3.2.2, as a temporary workaround, consider restricting access to the index.php file with the specified parameters until a patch is available. Avoid using the targetObjIdChild parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6562

Affected Products

Agora-Project