Apache OpenMeetings 3.1.0 Cross Site Scripting

2016.08.13
Credit: Matthew Daley
Risk: Low
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-79

Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings 3.1.0 Description: The value of the URL's "swf" query parameter is interpolated into the JavaScript tag without being escaped, leading to the reflected XSS. All users are recommended to upgrade to Apache OpenMeetings 3.1.2 Credit: This issue was identified by Matthew Daley Apache OpenMeetings Team


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top