PT-2020-10152 · Matrix42 · Matrix42 Workspace Management

Georg Ph E Heise

·

Published

2020-04-15

·

Updated

2020-04-22

·

CVE-2019-19390

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Matrix42 Workspace Management versions 9.1.2.2765 and below
Description The issue concerns the Search parameter in the Software Catalogue section, which accepts unfiltered parameters. This leads to multiple reflected XSS issues.
Recommendations For versions 9.1.2.2765 and below, consider restricting access to the Search parameter in the Software Catalogue section until a patch is available. As a temporary workaround, avoid using unfiltered parameters in the Search function to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19390

Affected Products

Matrix42 Workspace Management