KUNBUS PiCtory Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting vulnerability has been identified in KUNBUS PiCtory versions 2.11.1 and earlier. The issue arises from improper handling of the sso_token used for authentication. An attacker can exploit this vulnerability by sending a PiCtory URL that includes an HTML script in the sso_token. When the user accesses the URL, the script is executed in their browser.
Impact
Exploitation of this vulnerability allows for cross-site scripting attacks, where an attacker can inject and execute malicious scripts in the context of the user's session.
Remediation
Users are advised to update the PiCtory package to version 2.12. The update can be downloaded from the KUNBUS package repository. KUNBUS also plans to release a new Cockpit plugin by the end of April 2025 to assist with configurations. In the meantime, users should activate authentication.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
