Stark CRM Multiple Security Vulnerabilities
BID:65710
Info
Stark CRM Multiple Security Vulnerabilities
| Bugtraq ID: | 65710 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2014 12:00AM |
| Updated: | Feb 20 2014 12:00AM |
| Credit: | Gjoko 'LiquidWorm' Krstic |
| Vulnerable: |
IWCn Systems Inc Stark CRM 1.0 |
| Not Vulnerable: | |
Discussion
Stark CRM Multiple Security Vulnerabilities
Stark CRM is prone to the following security vulnerabilities:
1. Multiple HTML-injection vulnerabilities
2. Cross-Site Request-Forgery vulnerability
Exploiting these issues could allow an attacker to run malicious HTML and script codes, steal cookie-based authentication credentials, compromise the application or perform certain unauthorized actions that may aid in launching further attacks.
Stark CRM 1.0 is vulnerable; other versions may also be affected.
Stark CRM is prone to the following security vulnerabilities:
1. Multiple HTML-injection vulnerabilities
2. Cross-Site Request-Forgery vulnerability
Exploiting these issues could allow an attacker to run malicious HTML and script codes, steal cookie-based authentication credentials, compromise the application or perform certain unauthorized actions that may aid in launching further attacks.
Stark CRM 1.0 is vulnerable; other versions may also be affected.
Solution / Fix
Stark CRM Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].