PT-2017-2285 · Kaspersky · Kaspersky Anti-Virus

Published

2017-04-03

·

Updated

2017-04-03

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Kaspersky Anti-Virus 8.0 for Linux File Servers
Description The issue is related to a cross-site scripting vulnerability in the web console of Kaspersky Anti-Virus 8.0 for Linux File Servers. An attacker can exploit this by sending a specially crafted GET request that includes JavaScript code in the URL, which will then be executed in the client's browser.
Recommendations For Kaspersky Anti-Virus 8.0 for Linux File Servers, consider disabling the web console functionality until a patch is available to prevent potential exploitation. Restrict access to the web console to minimize the risk of malicious JavaScript code execution. Avoid using the web console for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01483

Affected Products

Kaspersky Anti-Virus