PT-2020-2446 · Unknown · Control Center Server
Published
2020-03-10
·
Updated
2024-01-09
·
CVE-2019-19294
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Control Center Server (CCS) versions prior to V1.5.0
Description
A stored Cross-site Scripting (XSS) vulnerability has been identified in the web interface of the Control Center Server (CCS). This issue is related to the lack of input data sanitization, which could allow an authenticated remote attacker to inject malicious JavaScript code into the CCS web application. The injected code would be executed in the browser context of any other user who views the relevant CCS web content.
Recommendations
For versions prior to V1.5.0, update to version V1.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the CCS web interface to minimize the risk of exploitation. Additionally, avoid using input fields that may be vulnerable to XSS attacks until the issue is resolved.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Control Center Server