VWE-2013-0012 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2013-0012
This page is a chapter in Info Known Vulnerabilities

This page has been seen 240,488 times.

    • Created by on
      Last updated by on
Common NameIdentity Theft Vulnerability
VWE-IDVWE-2013-0012
Related ReportNone
SeverityHIGH
Exploit DifficultyDifficult
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionHTML/Javascript injection. A user who does not have permission to use HTML in wiki comments posts a comment containing HTML. When another user who does have permission to use HTML in wiki comments views that user's comment, the HTML is rendered anyway.
DiscoveredApril 7, 2013
ResolvedApril 8, 2013
Patches Available4.0.0 Alpha 5
WorkaroundUpdate all areas so that HTML is not allowed in comments.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.