SrsX
Banned
Vulnerability discovered: 21/12/2013
Vulnerability public disclosure: 23/12/2013
Versions affected: All
ACL: Administrator
Critical: Semi/Partial
POC: Configuration -> General Settings -> Company Name -> VPS">board
Warnings: From here if an attacker wants they can figure out a way to execute raw javascript, if successful the frontend (public accessable end) may be executing raw javascript inplanted by the attacker.
Reported to vender: 21/12/2013
Image:
Vulnerability public disclosure: 23/12/2013
Versions affected: All
ACL: Administrator
Critical: Semi/Partial
POC: Configuration -> General Settings -> Company Name -> VPS">board
Warnings: From here if an attacker wants they can figure out a way to execute raw javascript, if successful the frontend (public accessable end) may be executing raw javascript inplanted by the attacker.
Reported to vender: 21/12/2013
Image:
Last edited by a moderator: