vendor:
GravCMS Core
by:
Ahsan Tahir
3,6
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: GravCMS Core
Affected Version From: 1.4.2
Affected Version To: 1.4.2
Patch Exists: YES
Related CWE: N/A
CPE: a:getgrav:grav_cms_core:1.4.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux 2.0, Windows 8.1
2017
GravCMS Core (Admin Plugin) v1.4.2 – Persistent Cross-Site Scripting
Ahsan Tahir, an independent vulnerability researcher discovered a Persistent Cross-Site Scripting Vulnerability in GravCMS Admin Plugin (v 1.4.2). The security risk of the xss vulnerability is estimated as medium with a common vulnerability scoring system count of 3.6. Exploitation of the persistent xss web vulnerability requires a limited admin user account and only low user interaction. Successful exploitation of the vulnerability results in persistent phishing attacks, session hijacking, persistent external redirect to malicious sources and persistent manipulation of affected or connected web module context.
Mitigation:
The vulnerability can be patched by a secure parse and encode of the vulnerable name parameter.