Apache OpenMeeting XSS Vulnerability (CVE-2016-2163)
Apache OpenMeeting XSS Vulnerability (CVE-2016-2163)
Release date:
Updated on:
Affected Systems:
Apache Group OpenMeetings <3.1.1
Description:
CVE (CAN) ID: CVE-2016-2163
Apache OpenMeetings is an audio and video conferencing software.
Apache OpenMeetings versions earlier than 3.1.1 have the cross-site scripting vulnerability. Remote attackers can inject arbitrary Web scripts or HTML files by using the event description when creating an event.
<* Source: Apache
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://www.apache.org/dist/openmeetings/3.1.1/CHANGELOG
Http://openmeetings.apache.org/security.html
Install OpenMeetings on a Linux/Unix system. Free video conference graphic tutorial
OpenMeetings Installation
OpenMeetings installation for Open-Source Video Conferencing Systems in Linux
Tutorial on building an OpenMeetings1.9 Video Conferencing System in Windows
For details about OpenMeetings, click here
OpenMeetings: click here
This article permanently updates the link address: