Get a Pentest and security assessment of your IT network.

News

Stored XSS in iframe allows less privileged users to do almost anything an admin can

CVE-2015-6739: The plugin is still vulnerable. The vendor has released version 4.0 in which onload is disabled, but the other event attributes are still permitted, including onpageshow. A number of these event attributes could be used to execute this attack, so this issue is not resolved. The plugin has been fixed but this does not address the issue.Disable the plugin until a new version is released that fixes this bug. You can read more about CVSS base scores on Wikipedia or in the CVSS specification.”]

Source: https://advisories.dxw.com/advisories/stored-xss-in-iframe-allows-less-privileged-users-to-do-almost-anything-an-admin-can/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Who and why is attacking companies in the Nordic Countries?

News

Shamoon Malware, cyber espionage tool, cyber weapon or