PT-2021-10811 · Apfell · Apfell

Mohamed A. Baset

+1

·

Published

2021-01-22

·

Updated

2021-01-29

·

CVE-2020-23014

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions APfell version 1.4
Description The issue allows for authenticated reflected cross-site scripting (XSS) through the payloadtypes callback function in the "/apiui/command " API endpoint. This enables an attacker to steal remote admin or user sessions and potentially add new users to the administration panel.
Recommendations For APfell version 1.4, consider disabling the payloadtypes callback function as a temporary workaround until a patch is available. Restrict access to the "/apiui/command " API endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23014

Affected Products

Apfell