PT-2023-10104 · Unknown · Stiiv Contact App
Published
2023-01-02
·
Updated
2024-05-17
·
CVE-2014-125034
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
stiiv contact app (affected versions not specified)
Description
A vulnerability has been found in stiiv contact app and classified as problematic. The function
render of the file libs/View.php is affected by this issue. The manipulation of the argument var leads to cross site scripting. The attack can be launched remotely.Recommendations
To fix this issue, it is recommended to apply a patch named 67bec33f559da9d41a1b45eb9e992bd8683a7f8c. As a temporary workaround, consider disabling the
render function of the libs/View.php file until the patch is applied. Restrict access to the var argument to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Stiiv Contact App