PT-2020-17167 · Unknown · Liveaddressplugin.Js
Published
2020-12-11
·
Updated
2020-12-14
·
CVE-2020-29455
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
liveAddressPlugin.js version 3.2
Description
A cross-Site Scripting (XSS) issue in
this.showInvalid and this.showInvalidCountry functions of liveAddressPlugin.js allows remote attackers to inject arbitrary web script or HTML via any address parameter, such as street or country.Recommendations
For liveAddressPlugin.js version 3.2, consider disabling the
this.showInvalid and this.showInvalidCountry functions as a temporary workaround until a patch is available. Restrict access to address parameters, such as street or country, to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Liveaddressplugin.Js