PT-2019-13228 · Xymon+1 · Xymon+1
Publicado
2019-08-26
·
Atualizado
2019-09-13
·
CVE-2019-13274
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Xymon versions prior to 4.3.29
Description
The issue is related to an XSS vulnerability in the csvinfo CGI script. This vulnerability exists due to insufficient filtering of the
db parameter.Recommendations
For versions prior to 4.3.29, update to version 4.3.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the csvinfo CGI script until a patch is available. Avoid using the
db parameter in the affected script until the issue is resolved.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Xymon