vendor:
Bedita
by:
Sébastien Morin
7.5
CVSS
HIGH
XSS
79
CWE
Product Name: Bedita
Affected Version From: 3.5.2001
Affected Version To: 3.5.2001
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2015
Bedita 3.5.1 XSS vulnerabilites
Bedita 3.5.1 contains multiples flaws that allows a persistent remote cross site scripting attack in the 'cfg[projectName]', 'data[stats_provider_url]' and 'data[description]' parameters. This could allow malicious users to create a specially crafted POST request that would execute arbitrary code in a user's browser in order to gather data from them or to modify the content of the page presented to the user.
Mitigation:
Upgrade to version 3.6 or later