HomeSecurityXSS vulnerability detected in popular web editor

XSS vulnerability detected in popular web editors

deep-web-black-market-criminal-identity-thief-wearing-gloves-at-a-keyboard

A tool that is particularly popular with Microsoft's in-house developers, the RadEditor HTML editor, contains a dangerous cross-site scripting (XSS) vulnerability, discovered by researcher GS McNamara.

The specific editor has been developed by Telerik and is used with confidential, internal code by many large enterprises, as well as in Redmond's products, including MSDN, CodePlex, TechNet, MCMS and as an alternative solution for SharePoint.

CGI Federal's McNamara said the vulnerability (CVE-2014-4958) was quite dangerous and could lead to typical XSS impacts, including the potential theft of personal information, sessions, and drive-by downloads.

The XSS was not immediately apparent and was not detectable by a known commercial vulnerability scanner.

McNamara is said to have contacted the company regarding the vulnerability, which initially denied its existence and urged the researcher to upgrade to a work around fix, which only addressed a portion of the vulnerability.

The researcher responded with exploit code and an email to the internal security team. A patch to address the vulnerability was released a month later, and the company publicly thanked McNamara for his research.

Detailed information about the vulnerability can be found on the Telerik blog: blogs.telerik.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS