Overview
MicroPact iComplaints contains a persistent cross-site scripting vulnerability.
Description
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') MicroPact iComplaints contains a persistent cross-site scripting vulnerability. The AddStdLetter.jsp file is vulnerable to script injection through the description parameter. |
Impact
A remote attacker may be able to execute arbitrary script in the context of the end-user's browser session. |
Solution
This issue has been patched in iComplaints version 8.0.2.1.8.8014. If you are unable to upgrade, please consider the following workaround: |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.9 | AV:N/AC:M/Au:S/C:P/I:P/A:N |
Temporal | 3.8 | E:F/RL:OF/RC:UR |
Environmental | 1.0 | CDP:N/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Michael Rutkowski of Merlin International for reporting this vulnerability.
This document was written by Todd Lewellen.
Other Information
CVE IDs: | CVE-2014-2971 |
Date Public: | 2014-07-21 |
Date First Published: | 2014-07-21 |
Date Last Updated: | 2014-07-21 20:23 UTC |
Document Revision: | 10 |