PT-2024-31067 · Cemipark · Cemipark
Dariusz Goåda
+1
·
Published
2024-05-09
·
Updated
2024-05-14
·
CVE-2024-4424
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CemiPark software versions 4.5, 4.7, 5.03
Description
The access control in CemiPark software does not properly validate user-entered data, allowing a stored cross-site scripting (XSS) attack. The parameters used to enter data into the system lack appropriate validation, making it possible to smuggle in HTML/JavaScript code, which will be executed in the user's browser space.
Recommendations
For version 4.5, update the input validation mechanism to properly check user-entered data.
For version 4.7, implement robust validation for all parameters to prevent XSS attacks.
For version 5.03, ensure that all user input is sanitized and validated to prevent code injection.
As a temporary workaround, consider restricting user input to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cemipark