Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.
References
Link | Resource |
---|---|
https://github.com/openmediavault/openmediavault/commit/b2db1e24d0e52b961b5c3b3329b6ee717cac53a2 | Patch Third Party Advisory |
https://github.com/openmediavault/openmediavault/commit/b2db1e24d0e52b961b5c3b3329b6ee717cac53a2 | Patch Third Party Advisory |
Configurations
History
21 Nov 2024, 03:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/openmediavault/openmediavault/commit/b2db1e24d0e52b961b5c3b3329b6ee717cac53a2 - Patch, Third Party Advisory |
Information
Published : 2017-07-17 13:18
Updated : 2024-11-21 03:04
NVD link : CVE-2017-1000065
Mitre link : CVE-2017-1000065
CVE.ORG link : CVE-2017-1000065
JSON object : View
Products Affected
openmediavault
- openmediavault
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')