2 results (0.012 seconds)

CVSS: 4.8EPSS: 0%CPEs: 1EXPL: 0

mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be vulnerable to XSS are only available to administrators who are supposed to have access to add scripts ** EN DISPUTA ** mojoPortal, hasta la versión 2.6.0.0 es propenso a múltiples vulnerabilidades de Cross-Site Scripting (XSS) debido a que fracasa a la hora de sanear entradas proporcionadas por el usuario. Los campos "Title" y "Subtitle" de la página "Blog" son vulnerables. NOTA: el mantenedor de software discute esta vulnerabilidad debido a que los campos que se indican como vulnerables a Cross-Site Scripting (XSS) están disponibles solamente a los administradores que deberían tener acceso para añadir scripts • http://www.securityfocus.com/bid/103263 https://github.com/i7MEDIA/mojoportal/issues/82 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 40EXPL: 1

Cross-site scripting (XSS) vulnerability in Forums/EditPost.aspx in mojoPortal before 2.3.9.8 allows remote attackers to inject arbitrary web script or HTML via the txtSubject parameter. Vulnerabilidad de XSS en Forums/EditPost.aspx en mojoPortal anterior a 2.3.9.8, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarias a través del parámetro "txtSubject". • http://archives.neohapsis.com/archives/bugtraq/2013-07/0200.html http://osvdb.org/95847 http://packetstormsecurity.com/files/122608/MojoPortal-2.3.9.7-Cross-Site-Scripting.html http://secunia.com/advisories/54297 http://www.securityfocus.com/bid/61520 https://exchange.xforce.ibmcloud.com/vulnerabilities/86058 https://www.mojoportal.com/mojoportal-2398-released • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •