PT-2021-21261 · Edifecs · Edifecs Transaction Management

Rvismit

·

Published

2021-07-12

·

Updated

2021-07-14

·

CVE-2021-36381

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Edifecs Transaction Management versions prior to 2021-07-12
Description The issue allows an unauthenticated user to inject arbitrary text into a user's browser via the "logon.jsp?logon error=" parameter on the login screen of the Web application. This is achieved by exploiting the login screen's functionality.
Recommendations For Edifecs Transaction Management versions prior to 2021-07-12, consider restricting access to the "logon.jsp" endpoint until a fix is available. As a temporary workaround, avoid using the "logon error" parameter in the login screen to minimize the risk of exploitation.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36381

Affected Products

Edifecs Transaction Management