First published: Tue Apr 28 2020(Updated: )
Open-AudIT 3.3.0 allows an XSS attack after login.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opmantek Open-AudIT | =3.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12261 is a vulnerability in Open-AudIT 3.3.0 that allows for a cross-site scripting (XSS) attack after login.
The severity of CVE-2020-12261 is medium with a CVSS score of 5.4.
CVE-2020-12261 affects Open-AudIT version 3.3.0.
To fix CVE-2020-12261, it is recommended to upgrade to Open-AudIT version 3.3.1 or later.
More information about CVE-2020-12261 can be found in the references provided: http://packetstormsecurity.com/files/157401/Open-AudIT-3.3.0-Cross-Site-Scripting.html, https://community.opmantek.com/display/OA/Errata+-+3.3.0+XSS+in+error+templates, https://community.opmantek.com/display/OA/Release+Notes+for+Open-AudIT+v3.3.1.