vendor:
DT Centrepiece
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting, Security Bypass
CWE
Product Name: DT Centrepiece
Affected Version From: DT Centrepiece 4.5
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
DT Centrepiece Multiple Vulnerabilities
DT Centrepiece is prone to multiple cross-site scripting vulnerabilities and multiple security-bypass vulnerabilities. An attacker may leverage the cross-site scripting issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. The attacker may leverage the security bypass issues to activate arbitrary accounts and gain unauthorized access to the affected application.
Mitigation:
No mitigation information provided