vendor:
Collabtive
by:
Anatolia Security
8,8
CVSS
HIGH
Non-persistent Cross-site Scripting and Cross-site Request Forgery
352, 79
CWE
Product Name: Collabtive
Affected Version From: 0.65
Affected Version To: 0.65
Patch Exists: YES
Related CWE: N/A
CPE: a:collabtive:collabtive
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
Collabtive Multiple Vulnerabilities
Application insert HTTP 'y' parameter in 'manageajax.php' and HTTP 'pic' parameter in 'thumb.php' into html output and fails while sanitize user supplied these inputs. Attackers can execute malicious javascript codes or hijacking PHPSESSID for privilege escalation. Attacker can create a specially crafted page and force collabtive administrators to visit it and can gain administrative privilege. For prevention from CSRF vulnerabilities, application needs anti-csrf token, captcha and asking old password for critical actions.
Mitigation:
Application needs anti-csrf token, captcha and asking old password for critical actions.