FirmChannel Digital Signage version 3.24 suffers from a cross site scripting vulnerability.
bcb35fe0a2c40a10309b3795346c219cd63abc3846b20cc4b2ddf929a5a51479
Title: FirmChannel Digital Signage 3.24 Cross-site scripting
-------------------------------------------------------------
Vendor: FirmChannel
Vendor URL: www.firmchannel.com
Vendor Response: Vendor has been notified and has since addressed the issue in the latest software release.
Description:
A cross-site scripting vulnerability is present within Firm Channel's Indoor & Outdoor Digital SIGNAGE version 3.24 (and potentially below).
Example:
http://host/index.php?module=account&action=login%3Cscript%3Ealert(%27xss%27);%3C/script%3E
Patch Information:
Firm Channel has addressed the issue in the latest version.
For more information visit firmchannel.com
CVE: CVE-2008-4931
Credit:
Brad Antoniewicz
brad.antoniewicz@foundstone.com