vendor:
Siebel CRM
by:
Sarath Nair aka AceNeon13
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Siebel CRM
Affected Version From: Siebel CRM (UI Framework) Version 19.0 and prior
Affected Version To: 19
Patch Exists: YES
Related CWE:
CPE: oracle:siebel_crm
Platforms Tested:
2019
Oracle Siebel CRM 19.0 – Persistent Cross-Site Scripting
The Siebel CRM application allows its users to upload any file types in most of the available file upload functionalities, later on, the uploaded file can be downloaded by another user with the appropriate privileges as part of the workflow. As such, it was possible to upload file with the “html” extension, (containing html and JavaScript code) thereby allowing to also perform Persistent Cross Site Scripting attack.
Mitigation:
Apply the Oracle Siebel CRM patch released on 16 July 2019