PT-2020-7920 · Ocportal · Ocportal

Arjun Basnet

·

Published

2020-08-03

·

Updated

2020-11-10

·

CVE-2015-9549

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: OcPortal version 9.0.20
Description: A reflected Cross-site Scripting (XSS) issue exists via the OCF EMOTICON CELL.tpl FIELD NAME field to "data/emoticons.php". This allows for potential malicious script injection.
Recommendations: For OcPortal version 9.0.20, consider disabling access to the "data/emoticons.php" endpoint or restricting the use of the FIELD NAME field in the OCF EMOTICON CELL.tpl template until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-9549

Affected Products

Ocportal