PT-2022-5013 · Crealogix · Crealogix Ebics
Tobias Ospelt
·
Published
2022-10-10
·
Updated
2022-10-11
·
CVE-2022-3442
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Crealogix EBICS version 7.0
Description
A vulnerability was found in the /ebics-server/ebics.aspx component of Crealogix EBICS, which can be exploited to conduct a cross-site scripting (XSS) attack. The attack may be launched remotely. The issue arises due to inadequate protection of the web page structure.
Recommendations
For Crealogix EBICS version 7.0, upgrade to version 7.1 to address this issue. As a temporary workaround, consider restricting access to the /ebics-server/ebics.aspx endpoint until the upgrade is applied.
Exploit
Fix
Improper Neutralization
Special Elements Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Crealogix Ebics