PT-2021-10599 · Rockoa · Rockoa

Published

2021-01-21

·

Updated

2021-01-30

·

CVE-2020-21147

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: RockOA version 1.9.8
Description: The issue allows remote attackers to send malicious code to the administrator and execute JavaScript code due to insufficient filtering in the webmain/flow/input/mode emailmAction.php file. This enables cross-site scripting (XSS) attacks.
Recommendations: For RockOA version 1.9.8, consider disabling access to the mode emailmAction.php file in the webmain/flow/input directory until a patch is available to prevent exploitation of the XSS vulnerability. Restrict input validation to minimize the risk of malicious code execution.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-21147

Affected Products

Rockoa