PT-2023-7520 · Aleos · Aleos
Published
2023-08-14
·
Updated
2023-12-08
·
CVE-2023-40461
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ALEOS versions 4.16 and earlier
Description
The issue is related to the ACEManager component of the ALEOS operating system, which does not properly validate file names in a file upload field. This can lead to a Stored Cross-Site Scripting condition, allowing a remote attacker to conduct inter-site script attacks. An authenticated user with Administrator privileges can access this vulnerable file upload field.
Recommendations
For ALEOS versions 4.16 and earlier, consider disabling the file upload field in the ACEManager component until a patch is available to fully validate file names and prevent Stored Cross-Site Scripting attacks. Restrict access to the ACEManager component to minimize the risk of exploitation. Avoid using the file upload feature in the affected versions until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Assertion Failure
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aleos