PT-2022-11618 · Unknown · Ctrlo Lenio

Published

2022-12-18

·

Updated

2022-12-22

·

CVE-2021-4256

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ctrlo lenio (affected versions not specified)
Description A vulnerability was found in ctrlo lenio, classified as problematic. It affects an unknown part of the file views/index.tt. The manipulation of the argument task.name/task.site.org.name leads to cross-site scripting. This attack can be initiated remotely.
Recommendations To fix this issue, it is recommended to apply a patch with the name e1646d5cd0a2fbab9eb505196dd2ca1c9e4cdd97. As a temporary workaround, consider restricting access to the vulnerable file views/index.tt until a patch is available. Additionally, avoid manipulating the task.name/task.site.org.name argument in the affected file to minimize the risk of exploitation.

Fix

XSS

Improper Neutralization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-4256

Affected Products

Ctrlo Lenio