PT-2020-10378 · Support Incident Tracker · Support Incident Tracker
Published
2020-01-02
·
Updated
2020-01-03
·
CVE-2019-20220
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Support Incident Tracker (SiT!) version 3.67
Description
The issue affects the search incidents advanced.php page, where the
search id parameter is vulnerable to XSS.Recommendations
For Support Incident Tracker (SiT!) version 3.67, avoid using the
search id parameter in the search incidents advanced.php page until the issue is resolved. As a temporary workaround, consider restricting access to the search incidents advanced.php page to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Support Incident Tracker