Posted by Steffen Rösemann on Jan 06
Advisory: Reflecting XSS vulnerability in CMS Sefrengo v.1.6.0
Advisory ID: SROEADV-2014-06
Author: Steffen Rösemann
Affected Software: CMS Sefrengo v.1.6.0
Vendor URL: http://www.sefrengo.org/
Vendor Status: solved
CVE-ID: –
==========================
Vulnerability Description:
==========================
The CMS Sefrengo v. 1.6.0 contains a reflecting XSS vulnerability in its
administrative backend.
==================
Technical Details:…