GroupLink everything HelpDesk Multiple Cross Site Scripting and Security Bypass Vulnerabilities
BID:62151
Info
GroupLink everything HelpDesk Multiple Cross Site Scripting and Security Bypass Vulnerabilities
| Bugtraq ID: | 62151 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2013 12:00AM |
| Updated: | Sep 12 2013 12:10AM |
| Credit: | V. Paulikas and J. Greil of SEC Consult Vulnerability Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
GroupLink everything HelpDesk Multiple Cross Site Scripting and Security Bypass Vulnerabilities
GroupLink everything HelpDesk is prone to multiple cross-site scripting vulnerabilities and a security-bypass vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials or bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
everything HelpDesk 10.0.3 and prior are vulnerable.
GroupLink everything HelpDesk is prone to multiple cross-site scripting vulnerabilities and a security-bypass vulnerability.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials or bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
everything HelpDesk 10.0.3 and prior are vulnerable.
Exploit / POC
GroupLink everything HelpDesk Multiple Cross Site Scripting and Security Bypass Vulnerabilities
Attackers can exploit security-bypass issue using a browser. To exploit cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
Attackers can exploit security-bypass issue using a browser. To exploit cross-site scripting issues, an attacker must entice an unsuspecting user to follow a malicious URI.
Solution / Fix
GroupLink everything HelpDesk Multiple Cross Site Scripting and Security Bypass Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
GroupLink everything HelpDesk Multiple Cross Site Scripting and Security Bypass Vulnerabilities
References:
References: