vendor:
agorum core Pro
by:
Dr. Erlijn van Genuchten & Sascha Grimmeisen, SySS GmbH
7,5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: agorum core Pro
Affected Version From: 7.8.1.4-251
Affected Version To: 7.8.1.4-251
Patch Exists: YES
Related CWE: Not yet assigned
CPE: agorum core Pro
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Persistent Cross-Site Scripting in agorum core Pro
Due to the possibility to upload HTML files that can include JavaScript attack vectors, the DMS is vulnerable to persistent cross-site scripting. In the desk4web module, users are able to upload files. For example, a file called 'xssattack.html' with the JavaScript code can be uploaded and when opened by other users, the included JavaScript code can be used to attack other users.
Mitigation:
Update to agorum core 7.11.3.