PT-2024-5537 · Unknown · Carbon Billing

Published

2024-06-21

·

Updated

2024-06-21

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Carbon Billing version 5
Description The issue is related to the lack of protection for the web page structure in the billing system interface. This can be exploited by a remote attacker to conduct a cross-site scripting (XSS) attack.
Recommendations For Carbon Billing version 5, consider implementing proper web page structure protection measures to prevent XSS attacks, such as validating and sanitizing user input and using appropriate encoding for user-generated content. As a temporary workaround, restrict access to sensitive areas of the web interface until a proper fix is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06203

Affected Products

Carbon Billing