Overview
QPR Portal versions 2014.1.1 and older contain reflected and stored cross-site scripting vulnerabilities, and versions 2012.2.0 and older contain an insecure direct object reference vulnerability.
Description
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') QPR Portal versions 2014.1.1 and older contain a stored cross-site scripting vulnerability (CVE-2014-8266) affecting the title and body fields of the note creation page. A reflected cross-site scripting vulnerability (CVE-2014-8267) affects the RID parameter. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary script in the context of the end-user's browser session or perform unauthorized operations on other users' notes. |
Solution
Apply an update |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Temporal | 3.4 | E:POC/RL:OF/RC:C |
Environmental | 2.5 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://www.qpr.com/products/qpr-suite-2014.htm
- http://files.qpr.com/hotfix/QPR_2014_1_1_Generic_402288.zip
- http://files.qpr.com/releases/QPR_Suite_2014.1.1/QPR_Suite_2014.1.1.zip
- http://files.qpr.com/releases/QPR_Suite_2012.2.1/QPR_Suite_2012.2.1.zip
- https://cwe.mitre.org/data/definitions/79.html
- https://cwe.mitre.org/data/definitions/639.html
Acknowledgements
Thanks to Mukhammad Khalilov of HelpAG for reporting these vulnerabilities.
This document was written by Joel Land.
Other Information
CVE IDs: | CVE-2014-8266, CVE-2014-8267, CVE-2014-8268 |
Date Public: | 2015-01-23 |
Date First Published: | 2015-01-23 |
Date Last Updated: | 2015-01-23 19:37 UTC |
Document Revision: | 18 |