PT-2021-10372 · Unknown · Racktables

Diego Di Nardo

·

Published

2021-12-07

·

Updated

2024-02-14

·

CVE-2020-19611

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Racktables version 0.21.2
Description: The issue allows an attacker to inject arbitrary web script or HTML via the op parameter in the redirect module. This enables the attacker to perform Cross Site Scripting (XSS) attacks.
Recommendations: For Racktables version 0.21.2, update to a version that fixes the Cross Site Scripting (XSS) issue in the redirect module, or as a temporary workaround, consider restricting access to the redirect module to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-19611

Affected Products

Racktables