vendor:
KrisonAV CMS
by:
High-Tech Bridge Security Research Lab
4.35.1
CVSS
MEDIUM
Cross-Site Scripting [CWE-79], Cross-Site Request Forgery [CWE-352]
79, 352
CWE
Product Name: KrisonAV CMS
Affected Version From: 3.0.1
Affected Version To: 3.0.1
Patch Exists: YES
Related CWE: CVE-2013-2712, CVE-2013-2713
CPE: a:krisonav:krisonav_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Multiple Vulnerabilities in KrisonAV CMS
The vulnerability exists due to insufficient filtration of user-supplied data passed to 'content' HTTP GET parameter via '/services/get_article.php' script. A remote attacker can trick a logged-in user to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of the vulnerable website. The vulnerability exists due to insufficient verification of the HTTP request origin in '/users_maint.html' script. A remote attacker can trick a logged-in administrator to visit a specially crafted webpage and create a new account with administrative privileges.
Mitigation:
Fixed by Vendor