OpenCA < 0.9.1-9 Web Interface Form Input Field XSS
Medium Nessus Network Monitor Plugin ID 2267
SynopsisThe remote host is vulnerable to an Cross-Site Scripting (XSS) attack.
DescriptionThe remote host appears to be running OpenCA. It is reported that OpenCA versions up to and including 0.9.2-RC2 are prone to a cross-site scripting vulnerability when processing user inputs into the web form frontend. This issue may permit an attacker to execute hostile HTML code in the context of another user.
SolutionUpgrade to version 0.9.1-9 or higher.