oss-sec mailing list archives

Persistent XSS in Mayan EDMS - document management system


From: Dolev Farhi <dolev () openflare org>
Date: Wed, 21 May 2014 18:46:37 +0300

Title: Multiple Stored XSS in Mayan EDMS - an open source document management system based on Python.


Vendor: Mayan EDMS - notified.


Homepage: www.mayan-edms.com


Date: 21.5.14


multiple persistent cross-site scripting vulnerabilities were found in the latest version of Mayan EDMS. it appears that new tags, folders and links that are created by any system user are not sanitized when viewed, allowing malicious code to be stored and executed.


advisory: http://research.openflare.org/advisories/mayan-edms/multiple_stored_xss.txt


Can CVE please be assigned to this?




Tx

Current thread: