PT-2020-13840 · Navigate · Navigate Cms

Renzi

·

Published

2020-06-24

·

Updated

2022-05-01

·

CVE-2020-14014

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Navigate CMS versions 2.8 through 2.9 r1433
Description An issue was discovered where the query parameter fid on the resource "navigate.php" does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.
Recommendations For Navigate CMS versions 2.8 through 2.9 r1433, consider validating and encoding the fid parameter in the "navigate.php" resource to prevent reflected XSS attacks. As a temporary workaround, restrict access to the "navigate.php" resource until a proper fix is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14014

Affected Products

Navigate Cms