vendor:
Ilch CMS
by:
High-Tech Bridge Security Research Lab
5,5
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Ilch CMS
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: YES
Related CWE: CVE-2014-1944
CPE: a:ilch:ilch_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Cross-Site Scripting (XSS) in Ilch CMS
The vulnerability exists due to insufficient sanitisation of user-supplied data in 'text' HTTP POST parameter passed to '/index.php/guestbook/index/newentry' URL. A remote unauthenticated user can send a specially crafted HTTP POST request, which allows to permanently inject and execute arbitrary HTML and script code in user's browser in context of the vulnerable website when the victim visits the 'http://[host]/index.php/guestbook/index/index' URL.
Mitigation:
Fixed by vendor on February 18, 2014 directly in the source code without version modification/new release.