PT-2021-10599 · Rockoa · Rockoa
Published
2021-01-21
·
Updated
2021-01-30
·
CVE-2020-21147
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
RockOA version 1.9.8
Description:
The issue allows remote attackers to send malicious code to the administrator and execute JavaScript code due to insufficient filtering in the webmain/flow/input/mode emailmAction.php file. This enables cross-site scripting (XSS) attacks.
Recommendations:
For RockOA version 1.9.8, consider disabling access to the mode emailmAction.php file in the webmain/flow/input directory until a patch is available to prevent exploitation of the XSS vulnerability. Restrict input validation to minimize the risk of malicious code execution.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rockoa