First published: Wed Dec 16 2020(Updated: )
A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is executed by an administrator.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Epson Eps Tse Server 8 Firmware | =21.0.11 | |
EPSON EPS TSE Server 8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28930 is a Cross-Site Scripting (XSS) vulnerability in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11).
The severity of CVE-2020-28930 is medium with a CVSS score of 5.4.
CVE-2020-28930 allows an authenticated attacker to inject a JavaScript payload in the user management page of EPSON EPS TSE Server 8 (21.0.11) that is executed by an administrator.
To fix CVE-2020-28930, apply the latest firmware update provided by EPSON for EPS TSE Server 8 (21.0.11) to address the Cross-Site Scripting (XSS) vulnerability.
More information about CVE-2020-28930 can be found at the following reference: https://blog.bssi.fr/multiple-vulnerabilities-within-epson-eps-tse-server-8/#vulnerability-2