Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tarek Awadallah

Researcher fromSySS GmbH
#47354of 53,638
5.4Total CVSS
Vulnerabilities · 1
PT-2022-12452
5.4
2022-03-13
Unknown · Ponton X/P Messenger · CVE-2021-45889
**Name of the Vulnerable Software and Affected Versions** PONTON X/P Messenger versions prior to 3.11.2 **Description** An issue was discovered in several functions, which are vulnerable to reflected XSS. This is demonstrated by various API endpoints, such as "private/index.jsp?partners/ShowNonLocalPartners.do?localID=", "private/index.jsp", "private/index.jsp?database/databaseTab.jsp", "private/index.jsp?activation/activationMainTab.jsp", "private/index.jsp?communication/serverTab.jsp", and "private/index.jsp?emailNotification/notificationTab.jsp". **Recommendations** For versions prior to 3.11.2, update to version 3.11.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable API endpoints until a patch is available. Avoid using the vulnerable functions in the affected API endpoints until the issue is resolved.