Reflecting XSS vulnerability in CMS Sefrengo v.1.6.0

Posted by Steffen Rösemann on Jan 06

Advisory: Reflecting XSS vulnerability in CMS Sefrengo v.1.6.0
Advisory ID: SROEADV-2014-06
Author: Steffen Rösemann
Affected Software: CMS Sefrengo v.1.6.0
Vendor URL: http://www.sefrengo.org/
Vendor Status: solved
CVE-ID: –

==========================
Vulnerability Description:
==========================

The CMS Sefrengo v. 1.6.0 contains a reflecting XSS vulnerability in its
administrative backend.

==================
Technical Details:…

Leave a Reply