CVE-2020-29144: XSS

Published Nov 27, 2020
·
Updated

In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via an Alert Dashboard comment. In most test cases, session hijacking was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover, or exploiting admins' browsers by using the beef framework.

Affected Software

2 affected components
Ericsson Bscs Ix R18 Billing \& Rating Admx
Ericsson Bscs Ix R18 Billing \& Rating Mx

Event History

Nov 27, 2020
CVE Published
via MITRE·03:35 AM
Data Sourced
via MITRE·03:35 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-29144?

CVE-2020-29144 is a vulnerability in Ericsson BSCS iX R18 Billing & Rating iX R18 MX, a web-based module that is vulnerable to stored XSS via an Alert Dashboard comment.

2

What is the severity of CVE-2020-29144?

The severity of CVE-2020-29144 is medium with a severity value of 5.4.

3

How can the stored XSS vulnerability in Ericsson BSCS iX R18 Billing & Rating iX R18 MX be exploited?

The stored XSS vulnerability in Ericsson BSCS iX R18 Billing & Rating iX R18 MX can be exploited through an Alert Dashboard comment, potentially allowing for session hijacking and full account takeover.

4

What is the affected software for CVE-2020-29144?

The affected software for CVE-2020-29144 is Ericsson Bscs Ix R18 Billing & Rating Admx and Ericsson Bscs Ix R18 Billing & Rating Mx.

5

Is there any fix available for CVE-2020-29144?

Please refer to the provided reference link for more information on any available fixes or patches for CVE-2020-29144.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203