Springshare LibCal 'api_events.php' Multiple Cross Site Scripting Vulnerabilities
BID:71319
Info
Springshare LibCal 'api_events.php' Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 71319 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7291 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2014 12:00AM |
| Updated: | Nov 25 2014 12:00AM |
| Credit: | Wang Jing |
| Vulnerable: |
Springshare LibCal 2.0 |
| Not Vulnerable: | |
Discussion
Springshare LibCal 'api_events.php' Multiple Cross Site Scripting Vulnerabilities
Springshare LibCal is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
LibCal 2.0 is vulnerable; other versions may also be affected.
Springshare LibCal is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
LibCal 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Springshare LibCal 'api_events.php' Multiple Cross Site Scripting Vulnerabilities
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Attackers can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
Solution / Fix
Springshare LibCal 'api_events.php' Multiple Cross Site Scripting Vulnerabilities
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.