PT-2020-13840 · Navigate · Navigate Cms
Renzi
·
Published
2020-06-24
·
Updated
2022-05-01
·
CVE-2020-14014
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Navigate CMS versions 2.8 through 2.9 r1433
Description
An issue was discovered where the query parameter
fid on the resource "navigate.php" does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.Recommendations
For Navigate CMS versions 2.8 through 2.9 r1433, consider validating and encoding the
fid parameter in the "navigate.php" resource to prevent reflected XSS attacks. As a temporary workaround, restrict access to the "navigate.php" resource until a proper fix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Navigate Cms