Lucene search

K
jvnJapan Vulnerability NotesJVN:04455183
HistoryAug 15, 2014 - 12:00 a.m.

JVN#04455183: Shutter vulnerable to cross-site scripting

2014-08-1500:00:00
Japan Vulnerability Notes
jvn.jp
70

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%

Shutter provided by tenfourzero is a web package allowing users to share their photos. Shutter contains a cross-site scripting vulnerability, which can be exploited through the SQL injection vulnerability (JVN#48039501).

Impact

If an administrator views a malicious page while logged in, an arbitrary script may be executed on the administrator’s web browser.

Solution

Uninstall the Software
According to the developer, the project is no longer being maintained and it is recommended to uninstall the software.

The developer states the following:
“As the project is not maintained it may be high unstable and insecure. You should therefore uninstall the software as soon as possible.”
``

Products Affected

  • Shutter v0.1.4
    Other versions may be affected.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%

Related for JVN:04455183