Alfresco CVE-2014-2939 HTML Injection and Cross Site Scripting vulnerabilities
BID:67678
Info
Alfresco CVE-2014-2939 HTML Injection and Cross Site Scripting vulnerabilities
| Bugtraq ID: | 67678 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2939 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2014 12:00AM |
| Updated: | May 28 2014 12:00AM |
| Credit: | Nicolas Verdier of the TEHTRI-Security |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Alfresco CVE-2014-2939 HTML Injection and Cross Site Scripting vulnerabilities
Alfresco is prone to an HTML-injection and a cross-site scripting vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Alfresco 4.1.6 is vulnerable; other versions may also be affected.
Alfresco is prone to an HTML-injection and a cross-site scripting vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Alfresco 4.1.6 is vulnerable; other versions may also be affected.
Exploit / POC
Alfresco CVE-2014-2939 HTML Injection and Cross Site Scripting vulnerabilities
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issue an attacker must entice an unsuspecting user into following a malicious URI.
Attackers can use a browser to exploit these issues. To exploit the cross-site scripting issue an attacker must entice an unsuspecting user into following a malicious URI.
Solution / Fix
Alfresco CVE-2014-2939 HTML Injection and Cross Site Scripting vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Alfresco CVE-2014-2939 HTML Injection and Cross Site Scripting vulnerabilities
References:
References: