activeCollab Planning Module Cross-Site Scripting and XQuery Injection Vulnerabilities
15 Jun. 2012
Summary
The Planning module for activeCollab is prone to a cross-site scripting vulnerability and a code-injection vulnerability because it fails to properly sanitize user-supplied input.
Credit:
The information has been provided by Andrew Horton, Steven Seeley, and Pedram Hayati, Stratsec.
The original article can be found at: http://www.securityfocus.com/bid/53746
An attacker may leverage these issues to manipulate XQuery queries and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks.
Vendor Status:
Currently we are not aware of any vendor-supplied patches.