PT-2020-16997 · Sentrifugo · Sentrifugo

·

CVE-2020-28365

·

Published

2020-12-30

·

Updated

2024-08-04

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sentrifugo version 3.2
Description The issue allows for Stored Cross-Site Scripting (XSS) by inserting a payload within the X-Forwarded-For HTTP header during the login process. When an administrator views logs, the payload is executed. This affects products that are no longer supported by the maintainer.
Recommendations For Sentrifugo version 3.2, as the product is no longer supported by the maintainer, there is no information about a newer version that contains a fix for this issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-28365

Affected Products

Sentrifugo