lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <201802201150.w1KBoKhs002170@ip-100-122-145-1.us-east-1.ec2.aws.symcpe.net>
Date: Tue, 20 Feb 2018 11:50:20 GMT
From: suparna.kachru@...il.com
To: bugtraq@...urityfocus.com
Subject: Multiple Persistent XSS vulnerabilities in Radiant Content
 Management System

*1. Introduction*

Vendor			: Radiant
Affected Product	: Radiant CMS 1.1.4
Fixed in		: NA
Vendor Website	       : http://radiantcms.org/
Vulnerability Type	: Persistent XSS
Remote Exploitable	: Yes
CVE External Identifier	: CVE-2018-7261	


*2. Overview*

Technical Description:

There are multiple Persistent XSS vulnerabilities in Radiant Content Management System. These vulnerabilities exists due to insufficient filtration/sanitization of user-supplied data. 


*3. Affected Modules*

This affects multiple parameters within:

1. Personal Preferences :  Name and Username
2. Configuration : Site Title, Dev Site Domain, Page Parts, and Page Fields

*4. Impact*

A remote attacker may leverage this issue to execute arbitrary script code in the browser of victim in the context of the affected CMS. 

*5. Payload*

<script>alert('XSS')</script>

*6. Credit*

Suparna Kachroo (@Sud0__su)

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ