PT-2021-10811 · Apfell · Apfell
Mohamed A. Baset
+1
·
Published
2021-01-22
·
Updated
2021-01-29
·
CVE-2020-23014
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
APfell version 1.4
Description
The issue allows for authenticated reflected cross-site scripting (XSS) through the
payloadtypes callback function in the "/apiui/command " API endpoint. This enables an attacker to steal remote admin or user sessions and potentially add new users to the administration panel.Recommendations
For APfell version 1.4, consider disabling the
payloadtypes callback function as a temporary workaround until a patch is available. Restrict access to the "/apiui/command " API endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apfell