PT-2020-17099 · Ericsson · Ericsson Bscs Ix
Aamir Rehman
·
Published
2020-11-27
·
Updated
2020-12-04
·
CVE-2020-29144
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ericsson BSCS iX R18 Billing & Rating iX R18
Description
The issue concerns a stored XSS vulnerability in the MX web-based module of Ericsson BSCS iX, specifically via an Alert Dashboard comment. This vulnerability can potentially lead to session hijacking, allowing for full account takeover. Additionally, it may enable exploiting admins' browsers using the beef framework.
Recommendations
For Ericsson BSCS iX R18 Billing & Rating iX R18, consider disabling the Alert Dashboard comment feature in the MX module until a patch is available to prevent exploitation of the stored XSS vulnerability. Restrict access to the MX module to minimize the risk of session hijacking and subsequent account takeover. Avoid using the Alert Dashboard comment feature in the affected module until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ericsson Bscs Ix