vendor:
ProcessMaker Workflow & BPM Software Suite
by:
Mickael Dorigny
8,8
CVSS
HIGH
Reflected XSS, Stored XSS, CSRF (x2)
352, 79, 352
CWE
Product Name: ProcessMaker Workflow & BPM Software Suite
Affected Version From: 3.0.1.7
Affected Version To: 3.0.1.7
Patch Exists: YES
Related CWE: N/A
CPE: a:processmaker:processmaker:3.0.1.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
ProcessMaker v3.0.1.7 Multiple vulnerabilities
ProcessMaker v3.0.1.7 is vulnerable to multiple vulnerabilities like Reflected XSS, Stored XSS, and CSRF (x2). One of the CSRF vulnerabilities is in the Designer Project Creation process, which can be exploited by a forged request to force an authenticated user with designer project creation rights to create a new Designer project.
Mitigation:
Ensure that all user input is properly validated and sanitized. Implement a strong access control policy and ensure that users are only granted access to the resources they need. Use a web application firewall to detect and block malicious requests.