PT-2019-12050 · Computrols · Cbas
Publicado
2019-05-23
·
Atualizado
2020-07-13
·
CVE-2019-10846
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Computrols CBAS version 18.0.0
Description
The issue allows for Unauthenticated Reflected Cross-Site Scripting in the login page and password reset page. This is achieved via the
username GET parameter in the API endpoint, specifically in the login and password reset pages.Recommendations
For Computrols CBAS version 18.0.0, consider disabling the login and password reset functionality until a patch is available to prevent exploitation via the
username parameter. Restrict access to these pages to minimize the risk of reflected Cross-Site Scripting attacks.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cbas