PT-2020-16992 · Sokrates · Sokrates Sowa Sowasql

Marek Holka

·

Published

2020-11-19

·

Updated

2020-11-27

·

CVE-2020-28350

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sokrates SOWA SowaSQL versions 5.6.1 and earlier
Description A Cross Site Scripting (XSS) issue exists in OPAC via the typ parameter in the "sowacgi.php" API endpoint.
Recommendations For versions 5.6.1 and earlier, consider restricting access to the sowacgi.php API endpoint until a patch is available. As a temporary workaround, avoid using the typ parameter in the affected API endpoint.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28350

Affected Products

Sokrates Sowa Sowasql