PT-2021-17403 · Opensips · Opensis Community Edition

Evan Yu

·

Published

2021-09-16

·

Updated

2021-09-27

·

CVE-2021-27340

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSIS Community Edition versions prior to 7.7
Description The issue is related to a reflected XSS vulnerability in the EmailCheck.php file, specifically via the opt parameter. This allows for potential exploitation.
Recommendations For OpenSIS Community Edition versions prior to 7.7, update to version 7.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the EmailCheck.php file until a patch is available. Avoid using the opt parameter in the affected EmailCheck.php file until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27340

Affected Products

Opensis Community Edition