vendor:
Secure Remote Access Base Software
by:
Malcrove
9.8
CVSS
CRITICAL
Reflected Cross-Site Scripting (XSS)
79
CWE
Product Name: Secure Remote Access Base Software
Affected Version From: v6.0
Affected Version To: v6.0.1
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2021
BeyondTrust Remote Support 6.0 – Reflected Cross-Site Scripting (XSS) (Unauthenticated)
Unauthenticated cross-site scripting (XSS) vulnerability in BeyondTrust Secure Remote Access Base Software through 6.0.1 allow remote attackers to inject arbitrary web script or HTML. Remote attackers could acheive full admin access to the appliance, by tricking the administrator into creating a new admin account through an XSS/CSRF attack involving a crafted request to the /appliance/users?action=edit endpoint.
Mitigation:
A fix has been released by the vendor in NSBase 6.1. It's recommended to update the vulnerable appliance base version to the latest version.