vendor:
eLineStudio Site Composer (ESC)
by:
AmnPardaz Security Research Team
7.5
CVSS
HIGH
Injection Flaws, Cross Site Scripting (XSS), SQL Injection, Information Leakage, Failure to Restrict URL Access
89, 79, 200, 285, 601
CWE
Product Name: eLineStudio Site Composer (ESC)
Affected Version From: 2.6 and prior versions
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
eLineStudio Site Composer (ESC) <=2.6 Multiple Vulnerabilities
eLineStudio Site Composer is a 100% browser-based database-driven content management system that helps companies to better manage, update & share web content. It has multiple vulnerabilities including injection flaws, cross-site scripting (XSS), SQL injection, information leakage, and failure to restrict URL access. These vulnerabilities can be exploited to perform various attacks such as SQL injection, XSS attacks, database path disclosure, and unauthorized access to server folders.
Mitigation:
The vendor has not provided a fix for these vulnerabilities. It is recommended to apply security patches or updates if available. Additionally, web application firewalls and input validation can help mitigate these vulnerabilities.