GLSA-200409-22 : phpGroupWare: XSS vulnerability in wiki module
Medium Nessus Plugin ID 14767
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-200409-22 (phpGroupWare: XSS vulnerability in wiki module)
Due to an input validation error, the wiki module in the phpGroupWare suite is vulnerable to cross site scripting attacks.
This vulnerability gives an attacker the ability to inject and execute malicious script code, potentially compromising the victim's browser.
The is no known workaround at this time.
SolutionAll phpGroupWare users should upgrade to the latest version:
# emerge sync # emerge -pv '>=www-apps/phpgroupware-0.9.16.003' # emerge '>=www-apps/phpgroupware-0.9.16.003'