We found results for “”
WS-2016-0045
Good to know:
Date: July 12, 2016
Versions 1.3.3 and below contain a cross site scripting vulnerability in the drag and drop functionality for modifying tree data. A node that contains a standard XSS vector will have its payload execute when a user attempts to drag a node to a different position in the hierarchy.
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix
Upgrade Version
Upgrade to version wislem/berrier - no_fix;nabble/ajde - v0.1;nabble/ajde - no_fix;su-sws/stanford_capx - 7.x-1.0;su-sws/stanford_capx - 7.3.0-beta10;su-sws/stanford_capx - 7.x-3.0-beta15;su-sws/stanford_capx - no_fix;su-sws/stanford_capx - 7.3.0-beta.15;ognestraz/admin - no_fix;majes/cms-bundle - no_fix;bigfoot/core-bundle - no_fix;bigfoot/core-bundle - v2.2.0;bigfoot/core-bundle - 1.0.0;forecho/yii2-jqtree - no_fix;jqtree - 1.3.4;ognestraz/lumen-admin - no_fix;webvimark/jqtreewidget - no_fix;Lionbridge.FlexFrame.WebUI - no_fix;org.webjars.npm:jqtree:1.4.2;org.webjars.bower:jqtree:no_fix
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


