vendor:
XODA Document Management System
by:
Shai rod
8,8
CVSS
HIGH
Stored XSS & Arbitrary File Upload
79
CWE
Product Name: XODA Document Management System
Affected Version From: 0.4.5
Affected Version To: 0.4.5
Patch Exists: YES
Related CWE: N/A
CPE: a:xoda:xoda
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
XODA Document Management System Stored XSS & Arbitrary File Upload Vulnerability
It is possible to access the file upload page '?upload_to=' without the need to authenticate (log in) to the XODA system. An attacker is able to upload a web shell to the server and gain unauzhorized access to the operating system. For the stored XSS, an attacker can enter a malicious payload in the file description or filters field and when the page is reloaded, the XSS will be triggered.
Mitigation:
Ensure that the application is updated to the latest version and that all security patches are applied. Restrict access to the file upload page and ensure that only authenticated users are allowed to upload files.