PT-2018-9571 · Freshdns · Freshdns
Luelistao
·
Published
2018-12-20
·
Updated
2019-01-08
·
CVE-2018-1000847
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FreshDNS versions 1.0.3 and prior
Description
The issue allows for the execution of an attacker's JavaScript code in a victim's session due to a Cross Site Scripting (XSS) vulnerability in the Account data form and Zone editor. This can be exploited when an attacker stores a specially crafted string as their Full Name in their account details, and the victim, such as the administrator, opens the User List in the admin interface.
Recommendations
For FreshDNS versions 1.0.3 and prior, update to version 1.0.5 or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freshdns