PT-2024-36337 · Kurmi · Kurmi Provisioning Suite
CVE-2024-54451
·
Published
2024-12-27
·
Updated
2024-12-28
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Kurmi Provisioning Suite versions 7.9.0.38 and earlier
Kurmi Provisioning Suite versions 7.10.x through 7.10.0.18
Kurmi Provisioning Suite versions 7.11.x through 7.11.0.15
Description:
A cross-site scripting (XSS) vulnerability in the graphicCustomization.do page allows remote attackers, authenticated as system administrators, to inject arbitrary web script or HTML via the
COMPONENT fields(htmlTitle) field. This field is rendered in other pages of the application for all users if the graphical customization has been activated by a super-administrator.Recommendations:
For Kurmi Provisioning Suite versions 7.9.0.38 and earlier, update to version 7.9.0.39 or later.
For Kurmi Provisioning Suite versions 7.10.x through 7.10.0.18, update to version 7.10.0.19 or later.
For Kurmi Provisioning Suite versions 7.11.x through 7.11.0.15, update to version 7.11.0.16 or later.
As a temporary workaround, consider restricting access to the graphicCustomization.do page until a patch is available.
Avoid using the
COMPONENT fields(htmlTitle) field in the graphicCustomization.do page until the issue is resolved.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kurmi Provisioning Suite