CVE-2020-29144: XSS
In Ericsson BSCS iX R18 Billing & Rating iX R18, MX is a web base module in BSCS iX that is vulnerable to stored XSS via an Alert Dashboard comment. In most test cases, session hijacking was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover, or exploiting admins' browsers by using the beef framework.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29144?
CVE-2020-29144 is a vulnerability in Ericsson BSCS iX R18 Billing & Rating iX R18 MX, a web-based module that is vulnerable to stored XSS via an Alert Dashboard comment.
What is the severity of CVE-2020-29144?
The severity of CVE-2020-29144 is medium with a severity value of 5.4.
How can the stored XSS vulnerability in Ericsson BSCS iX R18 Billing & Rating iX R18 MX be exploited?
The stored XSS vulnerability in Ericsson BSCS iX R18 Billing & Rating iX R18 MX can be exploited through an Alert Dashboard comment, potentially allowing for session hijacking and full account takeover.
What is the affected software for CVE-2020-29144?
The affected software for CVE-2020-29144 is Ericsson Bscs Ix R18 Billing & Rating Admx and Ericsson Bscs Ix R18 Billing & Rating Mx.
Is there any fix available for CVE-2020-29144?
Please refer to the provided reference link for more information on any available fixes or patches for CVE-2020-29144.