This site has moved to the integrated Appfire documentation and information site for our apps.

From February 2024 this site is no longer updated.

Take a look here! If you have any questions please email support@appfire.com

Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Current »

This advisory discloses a security vulnerability found and fixed in Comala Document Management.  We recommend upgrading Comala Document Management to the latest supported version.

Affected Versions

The vulnerability affects all versions of Comala Document Management up to 6.17.0

The 6.17.1 release contains a fix for the issue mentioned below.

XSS Vulnerabilities

Severity

Comalatech rates the severity of this issue as Medium according to the published Atlassian Security Levels.

We have ranked the vulnerability as Medium because

  • a registered user with edit permissions over pages or blog posts in the application could do the following: 

    • session riding

    • stealing information and cookies

    • creating a phishing page within the domain

This is an independent assessment and you should evaluate its applicability to your own IT environment.

Description

We have fixed a cross-site scripting vulnerability in Comala Document Management. The vulnerability could allow a user with edit permission to use another user's session.

Risk Mitigation

We recommend that all users upgrade Comala Document Management to at least v6.17.1.

  • No labels