PT-2019-13104 · Sahi · Sahi Pro

Published

2019-10-29

·

Updated

2019-11-06

·

CVE-2019-13066

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sahi Pro version 8.0.0
Description The issue concerns a reflected XSS vulnerability in the script manager arena, located at s /dyn/pro/DBReports. This vulnerability can be triggered by updating specific fields, including Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment. The sql parameter can also be used to trigger this issue.
Recommendations For Sahi Pro version 8.0.0, consider restricting access to the s /dyn/pro/DBReports area and avoid using the sql parameter in the affected endpoint until a fix is available. As a temporary workaround, restrict updates to the Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment fields to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-13066

Affected Products

Sahi Pro