DaDaBIK HTML Injection

  Bookmark
 and Share

DaDaBIK is a PHP-based application that allows users to create customizable front-end database interfaces. The module is exposed to an HTML injection issue because it fails to properly sanitize user-supplied input to the "html content" content type field or "rich_editor" field type field. DaDaBIK version 4.3 beta3 is affected.

Ref: https://bugzilla.redhat.com/show_bug.cgi?id=656756

10.49.38 - CVE: Not Available
Platform: Web Application