PT-2024-14062 · Kofax+1 · Capture+1
Dawid Maåecki
+3
·
Published
2024-01-11
·
Updated
2024-01-18
·
CVE-2023-5118
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Software versions prior to 11.1.x
Description
The application is vulnerable to Stored Cross-Site Scripting (XSS) in the endpoint "/sofer/DocumentService.asc/SaveAnnotation", where input data transmitted via the POST method in the parameters
author and text are not adequately sanitized and validated. This allows for the injection of malicious JavaScript code. The vulnerability was identified in the function for adding new annotations while editing document content.Recommendations
For versions prior to 11.1.x, update to a version above 11.1.x to resolve the issue. As a temporary workaround, consider restricting access to the "/sofer/DocumentService.asc/SaveAnnotation" endpoint or disabling the function for adding new annotations until a patch is available. Avoid using the parameters
author and text in the affected API endpoint until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Capture
Kofax Capture