Advisories

STVS ProVision 5.9.10 Authenticated Reflected Cross-Site Scripting via Files Parameter

Go Back
severity
medium
date
Affecting
  • STVS ProVision 5.9.10, 5.9.9, 5.9.7, 5.9.1, 5.9.0, 5.8.6, 5.7, 5.6, 5.5

CWE
  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS
4.8
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
Description
STVS ProVision 5.9.10 contains a cross-site scripting vulnerability in the 'files' POST parameter that allows authenticated attackers to inject arbitrary HTML code. Attackers can exploit the unvalidated input to execute malicious scripts within a user's browser session in the context of the affected site.