Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This advisory discloses a security vulnerability found and fixed in Comala Document Management.   We recommend upgrading Comala Document Management to the latest supported version.

...

The vulnerability affects Comala Document Management 6.4.0 → 6.13.0

The 6.13.1 release  release contains a fix for the issue mentioned below.

...

XSS Vulnerabilities

Severity

Comalatech rates the severity of these issues as Medium  according according to the published Atlassian Security Levels. We

We have ranked the vulnerability as medium because: 

  • A a registered user with edit permissions over pages or blog posts in the application could do the following: 
    • Session session riding
    • Stealing stealing information and cookies
    • Creating creating a phishing page within the domain

This is an independent assessment and you should evaluate its applicability to your own IT environment.

Description

We have fixed a cross-site scripting vulnerability introduced in Comala Document Management 6.4.0. The vulnerability could allow a any user with page level workflow usage permissions edit permission to use another user's session.

Risk Mitigation

Sites running 6.4.0-6.13.0 are recommend recommended to upgrade to Comala to Comala Document Management to 6.13.1.

If (red star) If upgrading immediately is not possible, please disable the application until you can upgrade it.