---
title: "Comala Document Approval Security Advisory 2020-12-14"
canonical: "https://support.appfire.com/space/CDALS/649626305/Comala%20Document%20Approval%20Security%20Advisory%202020-12-14"
format: markdown
---
This advisory discloses a security vulnerability found and fixed in Comala Document Approval. We recommend upgrading Comala Document Approval to the latest supported version.

## Affected Versions

The vulnerability affects **Comala Document Approval 1.4.0 → 1.7.11**

The **1.8.0 release contains a fix** for the issue mentioned below.

Versions prior to 1.4.0 are not affected.

## XSS Vulnerabilities

### Severity

<span style="color: #333333">Comalatech rates the severity of these issues as </span>**<span style="color: #333333">Medium</span>****<span style="color: #333333"> </span>**<span style="color: #333333"> according to the published </span>[<span style="color: #333333">Atlassian Security Levels</span>](https://www.atlassian.com/security/security-severity-levels)<span style="color: #333333">. We have ranked the vulnerability as medium because: </span>

- <span style="color: #333333">A registered user with edit permissions over pages or blog posts in the application could do the following: </span>
  - <span style="color: #333333">Session riding</span>
  - <span style="color: #333333">Stealing information and cookies</span>
  - <span style="color: #333333">Creating a phishing page within the domain</span>

<span style="color: #333333">This is an independent assessment and you should evaluate its applicability to your own IT environment.</span>

### Description

<span style="color: #333333">We have fixed a cross-site scripting vulnerability introduced in Comala Document Approval 1.4.0. The vulnerability could allow a user with page level workflow usage permissions to use another user's session.</span>

### Risk Mitigation

<span style="color: #333333">Sites running</span> 1.4.0-1.7.11 are recommend to upgrade to Comala Document Approval 1.8.0

<span style="color: #333333">If upgrading immediately is not possible please disable the application until you can upgrade it.</span>