phpCAS Cross-Site Scripting Vulnerability
BID:38883
Info
phpCAS Cross-Site Scripting Vulnerability
| Bugtraq ID: | 38883 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 22 2010 12:00AM |
| Updated: | Mar 29 2010 03:42PM |
| Credit: | An anonymous Drupal phpCAS module user. |
| Vulnerable: |
Red Hat Fedora 13 Red Hat Fedora 12 Red Hat Fedora 11 Moodle moodle 1.9.7 Jasig phpCAS 1.1 |
| Not Vulnerable: |
Moodle moodle 1.9.8 Moodle moodle 1.8.9 Jasig phpCAS 1.1 RC7 |
Discussion
phpCAS Cross-Site Scripting Vulnerability
phpCAS is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
phpCAS 1.1.0 is vulnerable; other versions may also be affected.
The following products that use phpCAS are affected:
Drupal phpCAS module
GLPI
phpCAS is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
phpCAS 1.1.0 is vulnerable; other versions may also be affected.
The following products that use phpCAS are affected:
Drupal phpCAS module
GLPI
Exploit / POC
phpCAS Cross-Site Scripting Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
phpCAS Cross-Site Scripting Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.