vendor:
ICU 7000-2
by:
Gjoko 'LiquidWorm' Krstic
N/A
CVSS
MEDIUM
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF)
79
CWE
Product Name: ICU 7000-2
Affected Version From: ICU Software: 1.00.08ICU OS: 1.3.8ICU File system: 1.3.8EIF Firmware [Channel 1]: 1.9EIF Firmware [Channel 2]: 1.9Iris TwoPi: 1.4.5
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: GNU/Linux 3.0.51 (armv7l), mylighttpd v1.0, PHP/5.5.13
2016
Iris ID IrisAccess ICU 7000-2 Multiple XSS and CSRF Vulnerabilities
The application is prone to multiple reflected cross-site scripting vulnerabilities due to a failure to properly sanitize user-supplied input to the 'HidChannelID' and 'HidVerForPHP' POST parameters in the 'SetSmarcardSettings.php' script. Attackers can exploit this issue to execute arbitrary HTML and script code in a user's browser session. The application also allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Mitigation:
The vendor has not provided a specific mitigation or remediation for this vulnerability.