Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

BigTree-CMS 4.2.x < 4.2.3 XSS

Medium

Synopsis

The version of BigTree-CMS running on the remote server is affected by a XSS vulnerability.

Description

The version of BigTree-CMS installed on the remote host is 4.2.x prior to 4.2.3 and is affected by a vulnerability that allows a stored XSS attack. This flaw exists because the user creation process does not validate input supplied as username and company name before returning it to users. This may allow a remote, authenticated attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server.

Solution

Upgrade to BigTree-CMS version 4.2.3 or later.