PT-2020-17100 · Ericsson · Ericsson Bscs Ix
Aamir Rehman
·
Published
2020-11-27
·
Updated
2020-12-04
·
CVE-2020-29145
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ericsson BSCS iX R18 Billing & Rating iX R18
Description
The issue concerns a stored XSS vulnerability in the ADMX web-based module, specifically via the
name or description field in the solutionUnitServlet?SuName=UserReferenceDataSU Access Rights Group endpoint. This vulnerability can potentially lead to session hijacking, allowing for full account takeover or exploiting administrators' browsers using the beef framework.Recommendations
For Ericsson BSCS iX R18 Billing & Rating iX R18, consider disabling access to the vulnerable
solutionUnitServlet endpoint until a fix is available, and restrict input for the name and description fields to prevent XSS attacks.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ericsson Bscs Ix