An issue was discovered in Jirafeau before 3.4.1. The "search file by link" form is affected by reflected XSS that could allow, by targeting an administrator, stealing a session and gaining administrative privileges.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-07-06T17:00:00Z

Updated: 2024-09-17T01:46:24.084Z

Reserved: 2018-07-06T00:00:00Z

Link: CVE-2018-13408

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-07-06T17:29:00.850

Modified: 2018-08-23T13:07:35.437

Link: CVE-2018-13408

cve-icon Redhat

No data.