---
title: "Comala Document Control Security Advisory 2022-09-28"
canonical: "https://support.appfire.com/space/COMALACDCLS/649893065/Comala%20Document%20Control%20Security%20Advisory%202022-09-28"
format: markdown
---
This advisory discloses a security vulnerability found and fixed in Comala Document Control.  We recommend upgrading Comala Document Control to the latest supported version.

## Affected Versions

The vulnerability affects all versions of **Comala Document Control up to 1.13.0**

The **[1.13.1](https://appfire.atlassian.net/wiki/spaces/COMALACDCLS/pages/649695749)**** release contains a fix** for the issue mentioned below.

## XSS Vulnerabilities

### Severity

Comalatech rates the severity of this issue as **Medium **according to the published [Atlassian Security Levels](https://www.atlassian.com/security/security-severity-levels).

We have ranked the vulnerability as **Medium** because

- a registered user with edit permissions over pages or blog posts in the application could do the following:
  - session riding
  - stealing information and cookies
  - creating a phishing page within the domain

This is an independent assessment and you should evaluate its applicability to your own IT environment.

### Description

We have fixed a cross-site scripting vulnerability in Comala Document Control. The vulnerability could allow a user with edit permission to use another user's session.

### Risk Mitigation

We recommend that all users upgrade Comala Document Control to at least **[1.13.1](https://appfire.atlassian.net/wiki/spaces/COMALACDCLS/pages/649695749)**.