PT-2022-11610 · Unknown · Ctrlo Lenio
Published
2022-12-18
·
Updated
2022-12-22
·
CVE-2021-4254
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ctrlo lenio (affected versions not specified)
Description
A vulnerability has been found in ctrlo lenio, classified as problematic, affecting an unknown functionality of the file views/layouts/main.tt of the component Notice Handler. The manipulation of the
notice.notice.text argument leads to cross-site scripting. The attack can be launched remotely.Recommendations
Apply a patch to fix this issue, specifically the patch named aa300555343c1c081951fcb68bfb6852fbba7451. As a temporary workaround, consider restricting the manipulation of the
notice.notice.text argument to minimize the risk of exploitation.Fix
Improper Neutralization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ctrlo Lenio