PT-2019-11505 · Servicestack · Servicestack Framework

Publicado

2019-07-23

·

Atualizado

2022-05-24

·

CVE-2019-1010199

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: ServiceStack ServiceStack Framework versions prior to 5.2.0
Description: The issue allows JavaScript to be reflected in the server response, which is then executed by the browser. This is due to a lack of server-side validation and the potential for browser encoding to be bypassed. The component vulnerable to this issue is the query used in the GET request. When a victim opens a crafted URL, they can be affected.
Recommendations: For versions prior to 5.2.0, update to version 5.2.0 to resolve the issue. As a temporary workaround, consider implementing server-side validation for the query used in the GET request to minimize the risk of exploitation. Restrict access to crafted URLs to prevent the execution of malicious JavaScript code.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-1010199
GHSA-VCFC-9WCP-J623

Produtos afetados

Servicestack Framework