PT-2020-10379 · Unknown · Support Incident Tracker
Published
2020-01-02
·
Updated
2020-01-03
·
CVE-2019-20221
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Support Incident Tracker (SiT!) version 3.67
Description
The issue affects the Load Plugins input in the config.php page, which is vulnerable to cross-site scripting (XSS). The XSS payload can be executed on the about.php page.
Recommendations
For version 3.67, consider restricting access to the config.php page and the about.php page until a fix is available. As a temporary workaround, avoid using the Load Plugins input in the config.php page to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Support Incident Tracker