PT-2020-16350 · Touchbase.Ai · Touchbase.Ai

Published

2020-11-11

·

Updated

2020-11-17

·

CVE-2020-26221

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions touchbase.ai versions prior to 2.0
Description The issue allows an attacker to send malicious JavaScript code, which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser actions.
Recommendations For versions prior to 2.0, update to version 2.0 to resolve the issue. As a temporary workaround, consider restricting access to sensitive user data and implementing additional security measures to prevent malicious JavaScript code execution.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26221
GHSA-JC3V-H36H-6MX3

Affected Products

Touchbase.Ai