PT-2019-12050 · Computrols · Cbas
Published
2019-05-23
·
Updated
2020-07-13
·
CVE-2019-10846
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Computrols CBAS version 18.0.0
Description
The issue allows for Unauthenticated Reflected Cross-Site Scripting in the login page and password reset page. This is achieved via the
username GET parameter in the API endpoint, specifically in the login and password reset pages.Recommendations
For Computrols CBAS version 18.0.0, consider disabling the login and password reset functionality until a patch is available to prevent exploitation via the
username parameter. Restrict access to these pages to minimize the risk of reflected Cross-Site Scripting attacks.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cbas