vendor:
Feng Office
by:
SecurityFocus
7,5
CVSS
HIGH
Security Bypass and HTML Injection
79, 352
CWE
Product Name: Feng Office
Affected Version From: Feng Office 2.2.1
Affected Version To: Feng Office 2.0 Beta 3
Patch Exists: Yes
Related CWE: N/A
CPE: a:fengoffice:feng_office
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
Feng Office Security Bypass and HTML Injection Vulnerabilities
Feng Office is prone to a security-bypass vulnerability and an HTML-injection vulnerability. An attacker may leverage the HTML-injection issue to inject hostile HTML and script code that would run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. The attacker may leverage the security-bypass issue to bypass certain security restrictions and perform unauthorized actions in the affected application.
Mitigation:
Users should apply the latest available updates to the affected application.