vendor:
Achievo
by:
Vulnerability-Lab Team (Chokri B.A.)
7.5
CVSS
HIGH
Cross-Site Scripting (XSS), Blind SQL Injection
79, 89
CWE
Product Name: Achievo
Affected Version From: 1.4.2003
Affected Version To: 1.4.2003
Patch Exists: NO
Related CWE:
CPE: a:achievo:achievo:1.4.3
Platforms Tested:
2012
Achievo v1.4.3 – Multiple Web Vulnerabilities
Multiple persistant cross site & a blind SQL vulnerabilities are detected on the resource management tool Achievo v1.4.3. The bug allows remote attacker to implement malicious script code on the application side and/or to execute sql commands via remote sql injection attack. Successful exploitation of the vulnerability allows an attacker to manipulate specific modules & can lead to session hijacking (user/mod/admin) and/or to compromise the application & dbms.
Mitigation:
Update to a patched version of Achievo or apply necessary security measures to prevent cross-site scripting and SQL injection attacks.