Cross-site Scripting (XSS) Vulnerabilities in Lantern CMS
Advisory ID: | HTB22620 |
Product: | Lantern CMS |
Vendor: | Lantern |
Vulnerable Versions: | 3.2.2 and probably prior and probably prior |
Tested Version: | 3.2.2 and probably prior |
Advisory Publication: | September 22, 2010 [without technical details] |
Vendor Notification: | September 22, 2010 |
Vendor Fix: | October 6, 2010 |
Public Disclosure: | October 6, 2010 |
Vulnerability Type: | Cross-Site Scripting [CWE-79] |
Risk Level: | Medium |
CVSSv2 Base Score: | 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) |
Solution Status: | Fixed by Vendor |
Discovered and Provided: | High-Tech Bridge Security Research Lab |
Advisory Details: | |
High-Tech Bridge SA Security Research Lab has discovered multiple vulnerabilities in Lantern CMS which could be exploited to perform cross-site scripting attacks. | |
Solution: | |
Upgrade to the most recent version | |
References: | |
[1] High-Tech Bridge Advisory HTB22620 - https://www.immuniweb.com/advisory/HTB22620 - Cross-site Scripting (XSS) Vulnerabilities in Lantern CMS [2] Lantern CMS - lanterncms.com - Lantern CMS has been built with one goal in mind: to make managing your website a pleasure. [3] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to developers and security practitioners, CWE is a formal list of software weakness types. | |
HTB22617: Cross-site Scripting (XSS) Vulnerabilities in Expression CMS
Please feel free to send us any additional information related to this Advisory, such as vulnerable versions, additional exploitation details and conditions, patches and other relevant details.