oss-sec mailing list archives
Persistent XSS in Mayan EDMS - document management system
From: Dolev Farhi <dolev () openflare org>
Date: Wed, 21 May 2014 18:46:37 +0300
Title: Multiple Stored XSS in Mayan EDMS - an open source document management system based on Python.
Vendor: Mayan EDMS - notified. Homepage: www.mayan-edms.com Date: 21.5.14multiple persistent cross-site scripting vulnerabilities were found in the latest version of Mayan EDMS. it appears that new tags, folders and links that are created by any system user are not sanitized when viewed, allowing malicious code to be stored and executed.
advisory: http://research.openflare.org/advisories/mayan-edms/multiple_stored_xss.txt
Can CVE please be assigned to this? Tx
Current thread:
- Persistent XSS in Mayan EDMS - document management system Dolev Farhi (May 21)
- Re: Persistent XSS in Mayan EDMS - document management system cve-assign (May 21)