PT-2020-20440 · Iteris · Iteris Vantage Velocity Field Unit

Published

2020-02-17

·

Updated

2020-02-19

·

CVE-2020-9025

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Iteris Vantage Velocity Field Unit version 2.4.2
Description The issue concerns multiple stored XSS problems in all parameters of the Start Data Viewer feature, specifically within the /cgi-bin/loaddata.py script.
Recommendations For Iteris Vantage Velocity Field Unit version 2.4.2, consider disabling access to the /cgi-bin/loaddata.py script until a fix is available, and restrict the use of the Start Data Viewer feature to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9025

Affected Products

Iteris Vantage Velocity Field Unit