PT-2024-11558 · Ovaledge · Ovaledge
Published
2024-10-25
·
Updated
2024-10-31
·
CVE-2022-30360
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OvalEdge versions 5.2.8.0 and earlier
Description
The issue is related to multiple Stored XSS (also known as Persistent or Type II) vulnerabilities. These vulnerabilities can be exploited via a POST request to the "/profile/updateProfile" API endpoint, specifically through the
slackid or phone parameters. It is noted that authentication is required to exploit this issue.Recommendations
For OvalEdge versions 5.2.8.0 and earlier, as a temporary workaround, consider disabling the
/profile/updateProfile API endpoint or restricting access to the slackid and phone parameters until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ovaledge