PT-2018-18172 · Epicentro · Epicentro
Fs
·
Published
2018-10-09
·
Updated
2018-12-10
·
CVE-2018-7633
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Epicentro versions 7.3.2 and later
Description
The issue concerns code injection in the "/ui/login" form, specifically through the
Language parameter, allowing attackers to execute JavaScript code. This is achieved by manipulating a user into issuing a POST request to the vulnerable endpoint.Recommendations
For Epicentro versions 7.3.2 and later, as a temporary workaround, consider restricting access to the "/ui/login" form or disabling the
Language parameter until a patch is available. Avoid using the Language parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epicentro