PT-2020-16686 · Opensips · Opensis Community Edition

Oliver Matula

·

Published

2020-12-04

·

Updated

2020-12-07

·

CVE-2020-27409

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSIS Community Edition versions prior to 7.5
Description The issue is a cross-site scripting (XSS) vulnerability in the SideForStudent.php file, specifically via the modname parameter. This allows for potential malicious script injection and execution.
Recommendations For OpenSIS Community Edition versions prior to 7.5, update to version 7.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the SideForStudent.php file or sanitizing input for the modname parameter until a patch is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27409

Affected Products

Opensis Community Edition