PT-2020-10768 · Cherokee · Cherokee

Mateusz Kocielski

+1

·

Published

2020-05-17

·

Updated

2022-11-21

·

CVE-2019-20798

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cherokee versions 1.2.104 and earlier
Description A cross-site scripting (XSS) issue was discovered in the handler server info.c file. The requested URL is improperly displayed on the About page in the default configuration of the web server and its administrator panel. This XSS issue can be used to reconfigure the server and execute arbitrary commands through the administrator panel.
Recommendations For Cherokee versions 1.2.104 and earlier, consider disabling the About page in the default configuration of the web server and its administrator panel as a temporary workaround until a patch is available. Restrict access to the administrator panel to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-20798

Affected Products

Cherokee