Sunday, September 19, 2010

ATutor: edit content folder XSS (Cross Site Scripting) vulnerability

Users of ATutor please be advised of an edit content folder XSS (Cross Site Scripting) vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
HTB22599: [HTB22599] XSS vulnerability in Atutor edit content folder
Product: ATutor
Vulnerability Type: XSS (Cross Site Scripting)
Vulnerability Details:

User can execute arbitrary JavaScript code within the vulnerable application.



The vulnerability exists due to failure in the "/mods/_core/editor/edit_content_folder.php" script to properly sanitize user-supplied input in "cid" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.
Read more at www.criticalwatch.com
 

No comments:

Post a Comment