vendor:
DzzOffice
by:
@nu11secur1ty
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: DzzOffice
Affected Version From: 2.02.1
Affected Version To: 2.02.1
Patch Exists: YES
Related CWE: CVE-2021-3318
CPE: a:dzzoffice:dzzoffice:2.02.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows, Linux, Mac
2021
DzzOffice 2.02.1 – ‘Multiple’ Cross-Site Scripting (XSS)
A Cross-Site Scripting (XSS) vulnerability exists in DzzOffice 2.02.1 which allows an attacker to inject malicious JavaScript code into the application. The vulnerability exists in the 'admin_password' parameter of the 'admin.php?mod=setting' page. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable page. The malicious JavaScript code will be executed in the browser of the victim when the vulnerable page is accessed.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to upgrade to the latest version of DzzOffice.