PT-2020-10172 · Matrix42 · Matrix42 Workspace Management
Christian Pappas
+1
·
Published
2020-04-15
·
Updated
2020-04-17
·
CVE-2019-19500
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Matrix42 Workspace Management versions 9.1.2.2765 and below
Description
The issue allows stored XSS via unfiltered description parameters, as demonstrated by the comment field of a special order for individual software. This can be exploited through the
description parameter in the comment field.Recommendations
For Matrix42 Workspace Management versions 9.1.2.2765 and below, consider disabling the comment field for special orders until a patch is available to prevent exploitation of the stored XSS vulnerability. Restrict access to the description parameters to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Matrix42 Workspace Management