Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in...
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in BEdita 3.4.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lrealname field in the editProfile form to index.php/home/profile; the (2) data[title] or (3) data[description] field in the addQuickItem form to index.php; the (4) "note text" field in the saveNote form to index.php/areas; or the (5) titleBEObject or (6) tagsArea field in the updateForm form to index.php/documents/view.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-1040
Credits & Attribution
No credits recorded in the NVD database.
References
- http://seclists.org/fulldisclosure/2015/Jan/16
- http://packetstormsecurity.com/files/129865/CMS-BEdita-3.4.0-Cross-Site-Scripting.html
- http://seclists.org/oss-sec/2015/q1/115
- https://github.com/bedita/bedita/issues/566
- http://sroesemann.blogspot.de/2014/12/sroeadv-2014-10.html
- http://www.securityfocus.com/bid/71949
More from bedita
View All →Affected Vendor
bedita
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.