PT-2017-13804 · Eyesofnetwork · Eyesofnetwork
Shaojiejiang
·
Published
2017-10-02
·
Updated
2021-02-23
·
CVE-2017-14985
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
EyesOfNetwork version 5.1-0
Description
The issue is related to a cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface. This allows remote authenticated users to inject arbitrary web script or HTML via the
url parameter to "module/module frame/index.php".Recommendations
For version 5.1-0, consider restricting access to the module frame/index.php module until a patch is available. As a temporary workaround, avoid using the
url parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eyesofnetwork