Blesta version 6 has been released! Read More.
All posts
Security 2013-10-07 · Cody · 1 min read

Security Advisory – Cross-site scripting vulnerabilities

Cross-site scripting advisory for Blesta 3.0.0 through 3.0.3: two message types render without sanitization. Both issues are fixed in the 3.0.4 patch.

Affected Versions

Versions 3.0.0 through 3.0.3 are affected.

Description

Some messages may be rendered without proper sanitization, making the system vulnerable to cross-site scripting (XSS) attacks through carefully crafted URLs. Two distinct message types are vulnerable to such an attack. Disabling PHP error reporting mitigates one of these vectors. Both issues are fully resolved in patch release 3.0.4.

Resolution

Upgrade to version 3.0.4. Related tasks:

  1. CORE-796
  2. CORE-797
Credits

Thanks to Vlad C. of NetSec Interactive Solutions for reporting these issues.

30-day free trial · No credit card · Your server

Read enough. Run it.

Everything on this blog ships in the box. Full product, free for 30 days, on your own server.

Download  6.0.0