Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Artem Brunov

Researcher fromTAL Australia
#21364of 53,633
11.5Total CVSS
Vulnerabilities · 2
Medium
2
PT-2020-20389
5.4
2020-02-26
Fiserv · Fiserv Accurate Reconciliation · CVE-2020-8951
**Name of the Vulnerable Software and Affected Versions** Fiserv Accurate Reconciliation versions prior to 3.0.0 **Description** The issue allows for XSS via the Source or Destination field of the Configuration Manager (Configuration Parameter Translation) page. **Recommendations** For versions prior to 3.0.0, update to version 3.0.0 or higher to resolve the issue.
PT-2020-20390
6.1
2020-02-26
Fiserv · Fiserv Accurate Reconciliation · CVE-2020-8952
**Name of the Vulnerable Software and Affected Versions** Fiserv Accurate Reconciliation versions prior to 3.0.0 **Description** The issue allows for cross-site scripting (XSS) attacks via the `timeOut` parameter in the `logout.jsp` endpoint. This could potentially lead to malicious script execution on the client-side. **Recommendations** For versions prior to 3.0.0, update to version 3.0.0 or higher to resolve the issue. As a temporary workaround, consider restricting access to the `logout.jsp` endpoint or avoiding the use of the `timeOut` parameter until the update is applied.