Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php.
| Software | From | Fixed in |
|---|---|---|
| codeworx_technologies / dcp-portal | 3.7 | 3.7.x |
| codeworx_technologies / dcp-portal | 4.1 | 4.1.x |
| codeworx_technologies / dcp-portal | 4.2 | 4.2.x |
| codeworx_technologies / dcp-portal | 4.0 | 4.0.x |