PT-2020-16997 · Sentrifugo · Sentrifugo

Luis Noriega

·

Published

2020-12-30

·

Updated

2024-08-04

·

CVE-2020-28365

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sentrifugo version 3.2
Description The issue allows for Stored Cross-Site Scripting (XSS) by inserting a payload within the X-Forwarded-For HTTP header during the login process. When an administrator views logs, the payload is executed. This affects products that are no longer supported by the maintainer.
Recommendations For Sentrifugo version 3.2, as the product is no longer supported by the maintainer, there is no information about a newer version that contains a fix for this issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-28365

Affected Products

Sentrifugo