PT-2020-13753 · Kordil · Kordil Edms

Published

2020-06-22

·

Updated

2020-06-26

·

CVE-2020-13888

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kordil EDMS versions through 2.2.60rc3
Description The issue allows stored XSS in several PHP files, including users edit.php, users management edit.php, and user management.php.
Recommendations For versions through 2.2.60rc3, consider disabling access to the users edit.php, users management edit.php, and user management.php files until a patch is available. Restrict input to prevent stored XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-13888

Affected Products

Kordil Edms