vendor:
UNA
by:
Greg.Priest
4.8
CVSS
MEDIUM
Stored XSS Vulnerability
79
CWE
Product Name: UNA
Affected Version From: UNA - 10.0.0-RC1
Affected Version To: UNA - 10.0.0-RC1
Patch Exists: YES
Related CWE: CVE-2019-14804
CPE: unaio/una
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows/Linux
2019
UNA – 10.0.0-RC1 stored XSS vuln.
Sign in to admin and look for the etemplates page (/studio/polyglot.php?page=etemplates)! Click Emails and edit the templates! Inject the JavaScript code into the System Name field!
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.