PT-2020-10152 · Matrix42 · Matrix42 Workspace Management
Georg Ph E Heise
·
Published
2020-04-15
·
Updated
2020-04-22
·
CVE-2019-19390
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Matrix42 Workspace Management versions 9.1.2.2765 and below
Description
The issue concerns the Search parameter in the Software Catalogue section, which accepts unfiltered parameters. This leads to multiple reflected XSS issues.
Recommendations
For versions 9.1.2.2765 and below, consider restricting access to the Search parameter in the Software Catalogue section until a patch is available. As a temporary workaround, avoid using unfiltered parameters in the Search function to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matrix42 Workspace Management