PT-2020-10355 · Determine · Contract Lifecycle Management

Esteban Rodriguez

·

Published

2020-01-05

·

Updated

2020-01-10

·

CVE-2019-20154

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Determine Contract Lifecycle Management (CLM) version 5.4
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML through multiple getchart.jsp parameters.
Recommendations For version 5.4, avoid using the vulnerable getchart.jsp parameters until a fix is available. As a temporary workaround, consider restricting access to the getchart.jsp endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-20154

Affected Products

Contract Lifecycle Management