PT-2023-11822 · Unknown · Geni Portal
Published
2023-01-18
·
Updated
2024-05-17
·
CVE-2020-36653
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GENI Portal (affected versions not specified)
Description
A problematic issue was found in GENI Portal, affecting some unknown functionality of the file portal/www/portal/error-text.php. The manipulation of the
error argument leads to cross-site scripting. The attack may be launched remotely.Recommendations
To fix this issue, it is recommended to apply a patch, specifically the one identified as c2356cc41260551073bfaa3a94d1ab074f554938. As a temporary workaround, consider restricting access to the vulnerable file portal/www/portal/error-text.php until a patch is applied. Additionally, avoid manipulating the
error argument in the affected functionality to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geni Portal