header-logo
Suggest Exploit
vendor:
TAO Open Source Assessment Platform
by:
Vulnerability Laboratory
4.0
CVSS
MEDIUM
Multiple Web Vulnerabilities
N/A
CWE
Product Name: TAO Open Source Assessment Platform
Affected Version From: 3.3.0 RC02
Affected Version To: 3.3.0 RC02
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Platforms Tested: N/A
2020

TAO Open Source Assessment Platform 3.3.0 RC02 – HTML Injection

Multiple cross site vulnerabilities have been discovered in the TAO Open Source Assessment Platform v3.3.0 RC02. The vulnerabilities allow remote attackers to inject malicious script codes on the application-side (persistent) of the vulnerable service module. The vulnerability is located in the `name` and `description` value of the `create` module. Remote attackers are able to inject own malicious script codes to the application-side of the vulnerable module. The execution of the script code occurs in the `list` module of the `create` module. The request method to inject is POST and the attack vector is located on the application-side.

Mitigation:

The vulnerability can be patched by a secure parse and encode of the `name` and `description` value of the `create` module.
Source

Exploit-DB raw data: