Overview :
Accentis Content Resource Management System versions released prior to the October 2015 patch suffer from a cross site scripting vulnerability.
Affected Product(s) :
  • Accentis Content Resource Management System
Vulnerability Details :
CVE ID : CVE-2015-3425
Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.

Remediation / Fixes :

Accentis Content Resource Management System before October 2015 patch contains Stored Cross-site scripting (XSS) vulnerability which allows authenticated users to inject arbitrary javascript via the following parameter.

# VULNERABLE PARAMETER:
– ctl00$cph_content$_uig_formState

# SAMPLE PAYLOAD
– <script>alert(“XSS”)</script>

# TIMELINE
– 15/04/2015: Vulnerability found
– 09/07/2015: Vendor informed
– 09/07/2015: Vendor responded and acknowledged
– 28/10/2015: Vendor fixed the issue
– 02/11/2015: Public disclosure