Lucene search

K
htbridgeHigh-Tech BridgeHTB23039
HistoryAug 17, 2011 - 12:00 a.m.

Cross-site Scripting (XSS) Vulnerability in Zikula Application Framework

2011-08-1700:00:00
High-Tech Bridge
www.htbridge.com
19

0.009 Low

EPSS

Percentile

82.9%

High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in Zikula Application Framework, which can be exploited to perform cross-site scripting attacks.

  1. Cross-site scripting (XSS) vulnerability in Zikula Application Framework
    Input passed via the “themename” parameter to “ztemp/view_compiled/Theme/theme_admin_setasdefault.php” is not properly sanitised before being returned to the user.
    This can be exploited to execute arbitrary HTML and script code in a administrator’s browser session in context of affected website.
    The following PoC code is available:
    http://host/index.php?module=theme&type=admin&func=setasdefault&themename=%3 Cscript%3Ealert%28document.cookie%29%3C/script%3E
CPENameOperatorVersion
zikula application frameworkle1.3.0

0.009 Low

EPSS

Percentile

82.9%

Related for HTB23039