PT-2019-5958 · Andover · Andover Continuum

Published

2019-11-20

·

Updated

2019-12-03

·

CVE-2019-6853

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Andover Continuum versions 9680, 5740, 5720, bCX4040, bCX9640, 9900, 9940, 9924, and 9702
Description The issue is related to the lack of input data sanitization, which can lead to Cross-site Scripting (XSS) attacks. This could allow a remote attacker to perform XSS attacks.
Recommendations For versions 9680, 5740, 5720, bCX4040, bCX9640, 9900, 9940, 9924, and 9702, consider restricting access to the web server as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03888
CVE-2019-6853

Affected Products

Andover Continuum