PT-2020-2446 · Unknown · Control Center Server

Published

2020-03-10

·

Updated

2024-01-09

·

CVE-2019-19294

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Control Center Server (CCS) versions prior to V1.5.0
Description A stored Cross-site Scripting (XSS) vulnerability has been identified in the web interface of the Control Center Server (CCS). This issue is related to the lack of input data sanitization, which could allow an authenticated remote attacker to inject malicious JavaScript code into the CCS web application. The injected code would be executed in the browser context of any other user who views the relevant CCS web content.
Recommendations For versions prior to V1.5.0, update to version V1.5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the CCS web interface to minimize the risk of exploitation. Additionally, avoid using input fields that may be vulnerable to XSS attacks until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2020-02456
CVE-2019-19294

Affected Products

Control Center Server