Date: Wed, 21 May 2014 18:46:37 +0300 From: Dolev Farhi <dolev@...nflare.org> To: cve-assign <cve-assign@...re.org>, oss-security@...ts.openwall.com Subject: Persistent XSS in Mayan EDMS - document management system Title: Multiple Stored XSS in Mayan EDMS - an open source document management system based on Python. Vendor: Mayan EDMS - notified. Homepage: www.mayan-edms.com Date: 21.5.14 multiple persistent cross-site scripting vulnerabilities were found in the latest version of Mayan EDMS. it appears that new tags, folders and links that are created by any system user are not sanitized when viewed, allowing malicious code to be stored and executed. advisory: http://research.openflare.org/advisories/mayan-edms/multiple_stored_xss.txt Can CVE please be assigned to this? Tx
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ