PYSEC-2014-110
Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.
Quick fix
PYSEC-2014-110 — mayan-edms: upgrade to the fixed version with the command below.
pip install --upgrade 'mayan-edms>=398c480c10416d76e7c1dcb607e726e8fc988e72'Details
Multiple cross-site scripting (XSS) vulnerabilities in apps/common/templates/calculate_form_title.html in Mayan EDMS 0.13 allow remote authenticated users to inject arbitrary web script or HTML via a (1) tag or the (2) title of a source in a Staging folder, (3) Name field in a bootstrap setup, or Title field in a (4) smart link or (5) web form.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/mayan-edms
Introduced in:
0Fixed in: 398c480c10416d76e7c1dcb607e726e8fc988e72Fix
pip install --upgrade 'mayan-edms>=398c480c10416d76e7c1dcb607e726e8fc988e72'References
- http://www.securityfocus.com/bid/67552[WEB]
- http://research.openflare.org/poc/maya-edms/maya-edms_multiple_xss.avi[WEB]
- http://research.openflare.org/advisories/OF-2014-09/mayan-edbs-storedxss.txt[EVIDENCE]
- https://github.com/mayan-edms/mayan-edms/issues/3[REPORT]
- http://seclists.org/oss-sec/2014/q2/349[WEB]
- http://seclists.org/oss-sec/2014/q2/352[WEB]
- https://github.com/mayan-edms/mayan-edms/commit/398c480c10416d76e7c1dcb607e726e8fc988e72[EVIDENCE]
- https://github.com/mayan-edms/mayan-edms/commit/398c480c10416d76e7c1dcb607e726e8fc988e72[FIX]
- http://www.exploit-db.com/exploits/33493[WEB]
- https://github.com/advisories/GHSA-wpvx-26f7-65q3[ADVISORY]