PT-2014-3360 · Algosec · Algosec Firewall Analyzer

Published

2014-01-29

·

Updated

2014-08-06

·

CVE-2013-7318

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions AlgoSec Firewall Analyzer version 6.4
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML via the message parameter in the BusinessFlow/login endpoint.
Recommendations For AlgoSec Firewall Analyzer version 6.4, avoid using the message parameter in the BusinessFlow/login endpoint until a fix is available. Consider restricting access to this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7318

Affected Products

Algosec Firewall Analyzer