Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <537CCA5D.4020900@openflare.org>
Date: Wed, 21 May 2014 18:46:37 +0300
From: Dolev Farhi <dolev@...nflare.org>
To: cve-assign <cve-assign@...re.org>, oss-security@...ts.openwall.com
Subject: Persistent XSS in Mayan EDMS - document management system

Title:  Multiple Stored XSS in Mayan EDMS - an open source document 
management system based on Python.


Vendor: Mayan EDMS - notified.


Homepage: www.mayan-edms.com


Date: 21.5.14


multiple persistent cross-site scripting vulnerabilities were found in 
the latest version of Mayan EDMS. it appears that new tags, folders and 
links that are created by any system user are not sanitized when viewed, 
allowing malicious code to be stored and executed.


advisory: 
http://research.openflare.org/advisories/mayan-edms/multiple_stored_xss.txt


Can CVE please be assigned to this?




Tx

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.