vendor:
CTERA Cloud Storage OS
by:
Luigi Vezzoso
8,8
CVSS
HIGH
Stored XSS
79
CWE
Product Name: CTERA Cloud Storage OS
Affected Version From: 3.2.29.0
Affected Version To: 3.2.42.0
Patch Exists: YES
Related CWE: CVE-2013-2639
CPE: a:ctera_networks:ctera_cloud_storage_os
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: ctera os
2013
CTERA Project Folders – Stored XSS
Standard Ctera User can define a particular “description” for a ProjectFolder that cause javascript code execution and HTML injection. User can forge particular description on Project Folder that permit XSS, HTML Injection (add of link, images, button ecc). As the project folder can be shared with different users that vulnerability permit the grabbing of sessions cookies.
Mitigation:
The vendor mark as resolved on latest CTERA version 4.x