Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-2639. PoCs published by Luigi Vezzoso.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in CTERA Project Folders. The vulnerability allows users to inject malicious JavaScript code via the description field of a Project Folder, potentially leading to session cookie theft.
Description
Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the description in a project folder.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in CTERA Project Folders. The vulnerability allows users to inject malicious JavaScript code via the description field of a Project Folder, potentially leading to session cookie theft.