Open Journal Systems Multiple HTML Injection Vulnerabilities
BID:43054
Info
Open Journal Systems Multiple HTML Injection Vulnerabilities
| Bugtraq ID: | 43054 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2010 12:00AM |
| Updated: | Jun 21 2011 04:10PM |
| Credit: | Sweet |
| Vulnerable: |
Public Knowledge Project Open Journal Systems 2.0 |
| Not Vulnerable: | |
Discussion
Open Journal Systems Multiple HTML Injection Vulnerabilities
Open Journal Systems is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Open Journal Systems 2.2.4 is vulnerable; other versions may also be affected.
UPDATE (June 21, 2011); The vendor refutes this issue stating an attacker requires administrative access to the affected application to exploit. This BID will be updated as more information emerges.
Open Journal Systems is prone to multiple HTML-injection vulnerabilities because the application fails to properly sanitize user-supplied input before using it in dynamically generated content.
Attacker-supplied HTML and script code would run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Open Journal Systems 2.2.4 is vulnerable; other versions may also be affected.
UPDATE (June 21, 2011); The vendor refutes this issue stating an attacker requires administrative access to the affected application to exploit. This BID will be updated as more information emerges.
Exploit / POC
Open Journal Systems Multiple HTML Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Open Journal Systems Multiple HTML Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
UPDATE (June 21, 2011); The vendor refutes this issue stating an attacker requires administrative access to the affected application to exploit. This BID will be updated as more information emerges.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
UPDATE (June 21, 2011); The vendor refutes this issue stating an attacker requires administrative access to the affected application to exploit. This BID will be updated as more information emerges.
References
Open Journal Systems Multiple HTML Injection Vulnerabilities
References:
References:
- Vendor Homepage (Public Knowledge Project)