Quantcast
Channel: Security Bulletins
Viewing all articles
Browse latest Browse all 25

Community Login URL Referer Reflected XSS Vulnerability

$
0
0

Publish Date: Feb. 21, 2019

Summary

We've identified and fixed an issue with the login URL of Spiceworks Community that could present a reflected cross-site scripting (XSS) vulnerability. This involves the referer parameter of the URL.

Who’s Affected?

At this time we do not believe anyone was impacted by this vulnerability.

Details

This exploit used a type of cross-site scripting (XSS) called reflected XSS. This is the most common type of XSS attack found throughout the internet. A reflected XSS attack allows an attacker to inject browser executable code through a single HTTP response. In this case, an attacker could send a login URL to the victim with the referrer parameter containing the malicious code. Upon clicking the link, the code would be executed, potentially compromising the victim.

Mitigating Factors

The victim would have to...


Viewing all articles
Browse latest Browse all 25

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>