PT-2020-10380 · Support Incident Tracker · Support Incident Tracker
Published
2020-01-02
·
Updated
2020-01-03
·
CVE-2019-20222
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Support Incident Tracker (SiT!) version 3.67
Description
The issue affects the Short Application Name and Application Name inputs in the config.php page, making them susceptible to XSS attacks.
Recommendations
For Support Incident Tracker (SiT!) version 3.67, consider validating and sanitizing user input for the Short Application Name and Application Name fields in the config.php page to prevent XSS attacks. As a temporary workaround, restrict access to the config.php page until a proper fix is applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Support Incident Tracker