Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2015-8766

MEDIUM · 6.1 CVSS Gepubliceerd: CWE-79

Beschrijving NL

Meerdere cross-site scripting (XSS) kwetsbaarheden in content/content.systempreferences.php in Symphony CMS vóór 2.6.4 staan externe aanvallers toe om willekeurig webscript of HTML te injecteren via de (1) email_sendmail[from_name], (2) email_sendmail[from_address], (3) email_smtp[from_name], (4) email_smtp[from_address], (5) email_smtp[host], (6) email_smtp[port], (7) jit_image_manipulation[trusted_external_sites], of (8) maintenance_mode[ip_whitelist] parameters naar systeem/voorkeuren .

Origineel (Engels) tonen

Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) email_sendmail[from_name], (2) email_sendmail[from_address], (3) email_smtp[from_name], (4) email_smtp[from_address], (5) email_smtp[host], (6) email_smtp[port], (7) jit_image_manipulation[trusted_external_sites], or (8) maintenance_mode[ip_whitelist] parameters to system/preferences.

Vendors

Getsymphony

Affected products

Symphony

References