PT-2021-21261 · Edifecs · Edifecs Transaction Management
Rvismit
·
Published
2021-07-12
·
Updated
2021-07-14
·
CVE-2021-36381
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Edifecs Transaction Management versions prior to 2021-07-12
Description
The issue allows an unauthenticated user to inject arbitrary text into a user's browser via the "logon.jsp?logon error=" parameter on the login screen of the Web application. This is achieved by exploiting the login screen's functionality.
Recommendations
For Edifecs Transaction Management versions prior to 2021-07-12, consider restricting access to the "logon.jsp" endpoint until a fix is available. As a temporary workaround, avoid using the "logon error" parameter in the login screen to minimize the risk of exploitation.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Edifecs Transaction Management