PT-2020-10381 · Support Incident Tracker · Support Incident Tracker
Published
2020-01-02
·
Updated
2020-01-03
·
CVE-2019-20223
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Support Incident Tracker (SiT!) version 3.67
Description
The issue affects the
id parameter, which is vulnerable to XSS on all endpoints that use this parameter.Recommendations
For Support Incident Tracker (SiT!) version 3.67, avoid using the
id parameter in affected API endpoints until the issue is resolved. As a temporary workaround, consider restricting access to endpoints that utilize the id parameter to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Support Incident Tracker