PT-2019-15276 · Zucchetti · Zucchetti Infobusiness

Published

2019-10-30

·

Updated

2019-11-06

·

CVE-2019-18207

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Zucchetti InfoBusiness versions prior to 4.4.2
Description The issue allows an authenticated user to inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. This code injection is triggered every time a user browses the reports page.
Recommendations For versions prior to 4.4.2, update to version 4.4.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the reports page or validating user input in the Title field to minimize the risk of code injection.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-18207

Affected Products

Zucchetti Infobusiness