Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 21 May 2014 18:46:37 +0300
From: Dolev Farhi <dolev@...nflare.org>
To: cve-assign <cve-assign@...re.org>, oss-security@...ts.openwall.com
Subject: Persistent XSS in Mayan EDMS - document management system

Title:  Multiple Stored XSS in Mayan EDMS - an open source document 
management system based on Python.


Vendor: Mayan EDMS - notified.


Homepage: www.mayan-edms.com


Date: 21.5.14


multiple persistent cross-site scripting vulnerabilities were found in 
the latest version of Mayan EDMS. it appears that new tags, folders and 
links that are created by any system user are not sanitized when viewed, 
allowing malicious code to be stored and executed.


advisory: 
http://research.openflare.org/advisories/mayan-edms/multiple_stored_xss.txt


Can CVE please be assigned to this?




Tx

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ