PT-2020-16923 · Pescms · Pescms Team

Published

2020-11-17

·

Updated

2020-12-01

·

CVE-2020-28092

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PESCMS Team version 2.3.2
Description The issue is related to multiple reflected XSS vulnerabilities via the id parameter in various API endpoints, including "/?g=Team&m=Task&a=my&status=3&id=", "/?g=Team&m=Task&a=my&status=0&id=", "/?g=Team&m=Task&a=my&status=1&id=", and "/?g=Team&m=Task&a=my&status=10&id=".
Recommendations For PESCMS Team version 2.3.2, consider restricting access to the id parameter in the affected API endpoints to minimize the risk of exploitation. As a temporary workaround, avoid using the id parameter in these endpoints until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28092

Affected Products

Pescms Team