PT-2019-11991 · Heidelberg · Prinect Archive System+1
Published
2019-05-06
·
Updated
2019-05-28
·
CVE-2019-10685
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Heidelberg Prinect Archiver version 2013 release 1.0
Prinect Archive System 2015 Release 2.6
Description
A Reflected Cross Site Scripting (XSS) issue was discovered. This issue allows for the execution of malicious scripts in the context of the affected system, potentially leading to unauthorized actions or data exposure.
Recommendations
For Heidelberg Prinect Archiver version 2013 release 1.0, update to a newer version that includes a fix for this issue.
For Prinect Archive System 2015 Release 2.6, update to a newer version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Heidelberg Prinect Archiver
Prinect Archive System