PT-2020-10172 · Matrix42 · Matrix42 Workspace Management

Christian Pappas

+1

·

Published

2020-04-15

·

Updated

2020-04-17

·

CVE-2019-19500

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Matrix42 Workspace Management versions 9.1.2.2765 and below
Description The issue allows stored XSS via unfiltered description parameters, as demonstrated by the comment field of a special order for individual software. This can be exploited through the description parameter in the comment field.
Recommendations For Matrix42 Workspace Management versions 9.1.2.2765 and below, consider disabling the comment field for special orders until a patch is available to prevent exploitation of the stored XSS vulnerability. Restrict access to the description parameters to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19500

Affected Products

Matrix42 Workspace Management