PT-2019-13228 · Xymon+1 · Xymon+1
Published
2019-08-26
·
Updated
2019-09-13
·
CVE-2019-13274
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Xymon versions prior to 4.3.29
Description
The issue is related to an XSS vulnerability in the csvinfo CGI script. This vulnerability exists due to insufficient filtering of the
db parameter.Recommendations
For versions prior to 4.3.29, update to version 4.3.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the csvinfo CGI script until a patch is available. Avoid using the
db parameter in the affected script until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Xymon