PT-2018-11094 · Ximdex · Ximdex
Whitehat001
·
Published
2018-06-13
·
Updated
2018-08-02
·
CVE-2018-12273
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ximdex version 4.0
Description
The issue concerns a security problem where the /edit URI in the DMS component is vulnerable to XSS attacks. This can be exploited via the
Ciudad or Nombre parameter.Recommendations
For Ximdex version 4.0, consider restricting access to the /edit URI in the DMS component to minimize the risk of exploitation. Avoid using the
Ciudad or Nombre parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ximdex