vendor:
PowerPanel Business Edition
by:
Joey Lane
CVSS
HIGH
Stored Cross Site Scripting
79
CWE
Product Name: PowerPanel Business Edition
Affected Version From: 3.4.0
Affected Version To: 3.4.0
Patch Exists: NO
Related CWE: Pending
CPE: a:cyberpower:powerpanel_business_edition
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 16.04
2019
PowerPanel Business Edition – Stored Cross Site Scripting (SNMP trap receivers)
CyberPower PowerPanel Business Edition 3.4.0 contains a stored cross site scripting vulnerability. The fields used to configure SNMP trap receivers are not being properly sanitized. This allows an authenticated user to inject arbitrary javascript code, which will later be executed once a user returns to the Event Action / Recipient page.
Mitigation:
Input validation should be used to ensure that user-supplied data is properly sanitized.