vendor:
Front Accounting
by:
Juan Manuel Garcia
5,8
CVSS
HIGH
Permanent Cross-Site Scripting (XSS)
79
CWE
Product Name: Front Accounting
Affected Version From: Front Accounting v2.3RC2
Affected Version To: Front Accounting v2.3RC2
Patch Exists: YES
Related CWE: N/A
CPE: a:frontaccounting:front_accounting
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Any running Front Accounting v2.3RC2
2010
Multiple Persistent Cross-Site Scripting (XSS) in Front Accounting
Multiple Persistent Cross-Site vulnerabilities were found in Front Accounting v2.3RC2, because the application fails to sanitize the response before it is returned to the user. This can be exploited to execute arbitrary script and HTML code in a user's browser session. This may allow the attacker to steal the user's cookie and to launch further attacks. The parameter 'trans_no' in /purchasing/allocations/supplier_allocate.php is not properly sanitized. The parameter 'PONumber' in /purchasing/po_receive_items.php is not properly sanitized. Other parameters might also be affected.
Mitigation:
The vendor has released a patch to fix this vulnerability.