PT-2020-2061 · Andover · Andover Continuum
Published
2020-03-10
·
Updated
2020-03-24
·
CVE-2020-7482
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Andover Continuum (All versions)
Description
A Cross-site Scripting vulnerability exists, which could cause a Reflective Cross-site Scripting attack when using the product's web server. This issue is related to the improper neutralization of input during web page generation, allowing a remote attacker to conduct an XSS attack. The vulnerability is associated with the lack of protection measures for the web page structure.
Recommendations
For all versions, consider disabling the web server functionality until a patch is available to prevent exploitation of the Cross-site Scripting vulnerability. Restrict access to the web server to minimize the risk of reflective XSS attacks. Avoid using the web server for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Andover Continuum