Description
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition allows remote attackers to inject arbitrary HTML or web script via (1) iframe, (2) img, or (3) object tags.
Product(s):
- WebCT Campus 4.0
- WebCT Campus 4.0 SP3 Hotfix 40833
- WebCT Campus 4.1.1.5
- WebCT Campus 4.1
- WebCT Campus 4.1 SP2 Hotfix 40832
Question to Ask Vendors:
- Can you confirm whether your systems are affected by CVE-2004-2015, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2004-2015 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions:
- Check out the advisory links provided below.