PT-2019-15018 · Intelliants · Subrion
Hacker625
·
Publicado
2019-10-06
·
Atualizado
2019-10-08
·
CVE-2019-17225
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Subrion version 4.2.1
Description
The issue allows for XSS attacks through the
panel/members/ endpoint, specifically via the Username, Full Name, or Email fields. This is related to an "Admin Member JSON Update" issue.Recommendations
For Subrion version 4.2.1, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the
panel/members/ endpoint to minimize the risk of exploitation. Avoid using the Username, Full Name, or Email fields in this endpoint until the issue is resolved.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Subrion