PT-2022-11663 · Unknown · Simplerisk
Published
2022-12-21
·
Updated
2022-12-27
·
CVE-2021-4269
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SimpleRisk versions prior to 20220306-001
Description
A vulnerability has been found in SimpleRisk, classified as problematic. It affects the function
checkAndSetValidation of the file simplerisk/js/common.js. The manipulation of the argument title leads to cross-site scripting. The attack can be initiated remotely.Recommendations
For versions prior to 20220306-001, upgrade to version 20220306-001 to address this issue. As a temporary workaround, consider disabling the
checkAndSetValidation function until the patch is applied. Restrict access to the simplerisk/js/common.js file to minimize the risk of exploitation. Avoid using the title argument in the affected function until the issue is resolved.Fix
XSS
Improper Neutralization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simplerisk