PT-2019-9503 · Grouptime · Grouptime Teamwire Client

Benjamin Braun

+4

·

Publicado

2019-06-28

·

Atualizado

2019-07-05

·

CVE-2018-17560

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Grouptime Teamwire Client versions 1.5.1 through 1.9.0 Grouptime Teamwire Client backend versions prior to prod-2018-11-13-15-00-42
Description The issue affects the admin interface of the Grouptime Teamwire Client, allowing stored XSS attacks.
Recommendations For Grouptime Teamwire Client versions 1.5.1 through 1.9.0, update to version 1.9.0 or later to resolve the issue. For Grouptime Teamwire Client backend versions prior to prod-2018-11-13-15-00-42, update to a version after prod-2018-11-13-15-00-42 to fix the problem.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17560

Produtos afetados

Grouptime Teamwire Client