PT-2019-6935 · Smokeping · Smokeping

Published

2019-11-01

·

Updated

2020-08-18

·

CVE-2013-4168

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SmokePing version 2.6.9
Description A cross-site scripting (XSS) issue exists in the start and end time fields, which could potentially allow attackers to inject malicious scripts into websites.
Recommendations For SmokePing version 2.6.9, update to a newer version that contains a fix for this issue, or as a temporary workaround, consider validating and sanitizing user input in the start and end time fields to prevent malicious script injection.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4168
DLA-348-1

Affected Products

Smokeping