PT-2017-6558 · Epicor · Epicor Crs Retail Store
Publicado
2017-09-06
·
Atualizado
2018-10-09
·
CVE-2015-2210
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Epicor CRS Retail Store versions prior to 3.2.03.01.008
Description
The issue allows local users to execute arbitrary code by injecting Javascript into the help window source, enabling the creation of a button that spawns a command shell.
Recommendations
For versions prior to 3.2.03.01.008, update to version 3.2.03.01.008 or later to resolve the issue.
Correção
Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Epicor Crs Retail Store