vendor:
DocuClass Enterprise Content Management
by:
Karn Ganeshen
8,8
CVSS
HIGH
SQL Injection, Access Control Flaws, Cross-Site Scripting
79, 89, 564
CWE
Product Name: DocuClass Enterprise Content Management
Affected Version From: All
Affected Version To: All
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows 2008 R2
2016
CIMA DocuClass Enterprise Content Management – Multiple Vulnerabilities
DocuClass is a modular and scalable enterprise content management (ECM) solution that allows organizations to streamline internal operations by significantly improving the way they manage their information within a business process. An unauthenticated attacker can read or modify data in the application database, execute code, and compromise the host system. An unauthenticated user can access stored documents by directly calling the document url. An unauthenticated attacker can execute malicious scripts in the user's browser.
Mitigation:
Enforce strict access control, input validation, and authentication.