vendor:
Phraseanet DAM Open Source software
by:
Krzysztof Szulski
5.5
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: Phraseanet DAM Open Source software
Affected Version From: 4.0.3
Affected Version To: 4.0.4-dev
Patch Exists: YES
Related CWE:
CPE: a:phraseanet:phraseanet
Platforms Tested:
2018
Stored XSS vulnerability in Phraseanet DAM Open Source software
A crafted file name for uploaded document leads to stored XSS. The file name should start from a double quotation mark and can contain malicious JavaScript code.
Mitigation:
Update the software to version 4.0.7 or above to fix the vulnerability. Avoid using special characters and sanitize user input to prevent XSS attacks.