PT-2020-7752 · Unknown · Tennisconnect Components

Published

2020-01-28

·

Updated

2020-01-30

·

CVE-2014-8490

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions TennisConnect COMPONENTS version 9.927
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the pid parameter to "index.cfm".
Recommendations For TennisConnect COMPONENTS version 9.927, avoid using the pid parameter in the "index.cfm" endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8490

Affected Products

Tennisconnect Components