KrisonAV CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
BID:59273
Info
KrisonAV CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
| Bugtraq ID: | 59273 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2712 CVE-2013-2713 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 17 2013 12:00AM |
| Updated: | Apr 18 2013 06:39AM |
| Credit: | High-Tech Bridge Security Research Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
KrisonAV CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
KrisonAV CMS is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.
KrisonAV CMS versions prior to 3.0.2 are vulnerable.
KrisonAV CMS is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, perform unauthorized actions, and disclose or modify sensitive information. Other attacks may also be possible.
KrisonAV CMS versions prior to 3.0.2 are vulnerable.
Exploit / POC
KrisonAV CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
To exploit these issues an attacker must entice an unsuspecting victim into following a malicious URI or visiting a malicious website.
To exploit these issues an attacker must entice an unsuspecting victim into following a malicious URI or visiting a malicious website.
Solution / Fix
KrisonAV CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
KrisonAV CMS Cross Site Scripting and Cross Site Request Forgery Vulnerabilities
References:
References: