PT-2022-4411 · Bpc · Bpc Smartvista

Tf1T

+1

·

Published

2022-07-07

·

Updated

2022-08-22

·

CVE-2022-35554

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions BPC SmartVista version 3.28.0
Description The issue concerns reflected XSS vulnerabilities in error message handling, allowing an attacker to execute JavaScript code on the client side. Additionally, there is a vulnerability in the SmartVista CardGen personalization module due to inadequate protection of the web page structure, which can be exploited for cross-site scripting (XSS) attacks.
Recommendations For BPC SmartVista version 3.28.0, consider disabling the error message handling feature until a patch is available to prevent exploitation of the reflected XSS vulnerability. Restrict access to the SmartVista CardGen personalization module to minimize the risk of XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-05275
CVE-2022-35554

Affected Products

Bpc Smartvista