PT-2019-13104 · Sahi · Sahi Pro
Published
2019-10-29
·
Updated
2019-11-06
·
CVE-2019-13066
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sahi Pro version 8.0.0
Description
The issue concerns a reflected XSS vulnerability in the script manager arena, located at
s /dyn/pro/DBReports. This vulnerability can be triggered by updating specific fields, including Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment. The sql parameter can also be used to trigger this issue.Recommendations
For Sahi Pro version 8.0.0, consider restricting access to the
s /dyn/pro/DBReports area and avoid using the sql parameter in the affected endpoint until a fix is available. As a temporary workaround, restrict updates to the Script Name, Suite Name, Base URL, Android, iOS, Scripts Run, Origin Machine, or Comment fields to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sahi Pro