VWE-2015-1636 Printable Version

https://www.vaultwiki.org/pages/Book/Documentation/VWE-2015-1636
This page is a chapter in Info Known Vulnerabilities

This page has been seen 283,191 times.

    • Created by on
      Last updated by on
Common NamePlagiarizer Vulnerability
VWE-IDVWE-2015-1636
Related ReportNone
SeverityHIGH
Exploit DifficultyNORMAL
PlatformAffects all platforms supported by the vulnerable versions.
DescriptionHTML/Javascript injection via Permissions escalation.
DiscoveredOctober 12, 2015
ResolvedOctober 14, 2015
Patches Available4.0.6 Patch Level 3
4.0.5 Patch Level 3
4.0.4 Patch Level 3
4.0.3 Patch Level 3
4.0.2 Patch Level 6
4.0.1 Patch Level 9
4.0.0 Patch Level 8
4.0.0 RC 5 Patch Level 7
4.0.0 RC 4 Patch Level 8
WorkaroundModify permissions so that no users may post HTML in comments.
The versions listed below are known to be affected by this issue. If you are using one of those versions, you should update to a newer release that has no known vulnerabilities.