PT-2020-14898 · Red Hat+1 · Pki-Core+1
Published
2020-03-20
·
Updated
2023-02-12
·
CVE-2020-1696
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
pki-core versions 10.x.x
Description
A flaw was found in the Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability when the profile ID is printed. An attacker with sufficient permissions could trick an authenticated victim into executing a specially crafted Javascript code.
Recommendations
For pki-core versions 10.x.x, ensure that Profile IDs are properly sanitized to prevent Stored Cross-Site Scripting (XSS) attacks. As a temporary workaround, consider restricting access to the Token Processing Service (TPS) until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Pki-Core