---
title: "Comala Document Management Security Advisory 2022-09-28"
canonical: "https://support.appfire.com/space/CDML/650316592/Comala%20Document%20Management%20Security%20Advisory%202022-09-28"
format: markdown
---
> Macro (aura-html)


This advisory discloses a security vulnerability found and fixed in Comala Document Management.  We recommend upgrading Comala Document Management to the latest supported version.

## Affected Versions

The vulnerability affects all versions of **Comala Document Management up to 6.17.0**

The **[6.17.1](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649857432)**** release contains a fix** for the issue mentioned below.

## XSS Vulnerabilities

### Severity

Comalatech rates the severity of this issue as **Medium **according to the published [Atlassian Security Levels](https://www.atlassian.com/security/security-severity-levels).

We have ranked the vulnerability as **Medium** because

- a registered user with edit permissions over pages or blog posts in the application could do the following:
  - session riding
  - stealing information and cookies
  - creating a phishing page within the domain

This is an independent assessment and you should evaluate its applicability to your own IT environment.

### Description

We have fixed a cross-site scripting vulnerability in Comala Document Management. The vulnerability could allow a user with edit permission to use another user's session.

### Risk Mitigation

We recommend that all users upgrade Comala Document Management to at least [v6.17.1](https://appfire.atlassian.net/wiki/spaces/CDML/pages/649857432).