PT-2021-10493 · Unknown · White Shark System

Published

2021-06-21

·

Updated

2022-09-29

·

CVE-2020-20467

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: White Shark System (WSS) version 1.3.2
Description: The issue allows remote attackers to exploit the vulnerability and create a task, leading to sensitive information disclosure via the default task add.php endpoint. The default task add.php endpoint is vulnerable to this issue.
Recommendations: For White Shark System (WSS) version 1.3.2, consider restricting access to the default task add.php endpoint until a patch is available. As a temporary workaround, avoid using the default task add.php endpoint to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2020-20467

Affected Products

White Shark System