Piwik < 2.16.1-rc1 Multiple Vulnerabilities

critical Nessus Plugin ID 90538

Synopsis

A web application hosted on the remote web server is affected by multiple vulnerabilities.

Description

The version of Piwik running on the remote web host is prior to version 2.16.1-rc1. It is, therefore, affected by multiple vulnerabilities :

- An unspecified flaw exists that may allow an attacker to have a critical impact. No further details are available.

- Multiple unspecified cross-site scripting (XSS) vulnerabilities exist due to a failure to properly validate input before returning it to users. An unauthenticated, remote attacker can exploit these, via a crafted request, to execute arbitrary script code in a user's browser session.

Solution

Upgrade to Piwik version 2.16.1-rc1 or later. If necessary, remove any affected versions.

See Also

http://piwik.org/changelog/piwik-2-16-1/

Plugin Details

Severity: Critical

ID: 90538

File Name: piwik_2_16_1.nasl

Version: 1.7

Type: remote

Family: CGI abuses

Published: 4/15/2016

Updated: 4/11/2022

Configuration: Enable thorough checks

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:piwik:piwik

Required KB Items: www/PHP, installed_sw/Piwik

Patch Publication Date: 4/1/2016

Vulnerability Publication Date: 4/1/2016