PT-2020-2061 · Andover · Andover Continuum

Published

2020-03-10

·

Updated

2020-03-24

·

CVE-2020-7482

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Andover Continuum (All versions)
Description A Cross-site Scripting vulnerability exists, which could cause a Reflective Cross-site Scripting attack when using the product's web server. This issue is related to the improper neutralization of input during web page generation, allowing a remote attacker to conduct an XSS attack. The vulnerability is associated with the lack of protection measures for the web page structure.
Recommendations For all versions, consider disabling the web server functionality until a patch is available to prevent exploitation of the Cross-site Scripting vulnerability. Restrict access to the web server to minimize the risk of reflective XSS attacks. Avoid using the web server for sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01894
CVE-2020-7482

Affected Products

Andover Continuum