PT-2017-14580 · Icon Time Systems · Icon Time Systems Rtc-1000

Publicado

2017-11-17

·

Atualizado

2017-12-04

·

CVE-2017-16819

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Icon Time Systems RTC-1000 versions 2.5.7458 and earlier
Description A stored cross-site scripting issue allows remote attackers to inject arbitrary JavaScript in the nameFirst field for the employee details page ("/employee.html") that is then reflected in multiple pages where that field data is utilized, resulting in session hijacking and possible elevation of privileges.
Recommendations For Icon Time Systems RTC-1000 versions 2.5.7458 and earlier, as a temporary workaround, consider restricting access to the /employee.html page and avoid using the nameFirst field until a patch is available.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-16819

Produtos afetados

Icon Time Systems Rtc-1000