PT-2021-11907 · Unknown · Bdtask Multi-Store Inventory Management System
Published
2021-01-27
·
Updated
2021-01-29
·
CVE-2020-36012
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
BDTASK Multi-Store Inventory Management System version 1.0
Description:
The issue allows a local admin to inject arbitrary code via the
Customer Name Field. This enables the execution of malicious scripts, potentially leading to unauthorized access or data manipulation.Recommendations:
For BDTASK Multi-Store Inventory Management System version 1.0, consider restricting access to the
Customer Name Field to prevent arbitrary code injection until a patch is available. As a temporary workaround, validate and sanitize all user input in the Customer Name Field to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bdtask Multi-Store Inventory Management System