vendor:
RuubikCMS
by:
7.5
CVSS
HIGH
Cross-Site Scripting (XSS), Information Disclosure, Directory Traversal
79 (Cross-Site Scripting), 22 (Path Traversal), 200 (Information Exposure)
CWE
Product Name: RuubikCMS
Affected Version From: 1.1.2000
Affected Version To: 1.1.2001
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
RuubikCMS Multiple Vulnerabilities
Attackers can steal cookie-based authentication credentials, execute arbitrary script code in the browser, and retrieve arbitrary files from the affected system. This can lead to the disclosure of sensitive information and other possible attacks.
Mitigation:
Update to version 1.1.2 or later. Implement input validation and output encoding to prevent XSS attacks. Restrict access to sensitive files and directories.