vendor:
ClearPass Policy Manager
by:
Cristiano Maruti
5.5
CVSS
MEDIUM
Stored cross-site script
79
CWE
Product Name: ClearPass Policy Manager
Affected Version From: Aruba ClearPass Policy Manager 6.4
Affected Version To: Aruba ClearPass Policy Manager 6.4
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2014
ClearPass Policy Manager Stored XSS
The analysis discovered a stored cross site scripting vulnerability (OWASP OTG-INPVAL-002) in the ClearPass Policy Manager. A malicious unauthenticated user is able to inject arbitrary script through the login form that may be rendered and triggered later if a privileged authenticated user reviews the access audit record. An attack can use the aforementioned vulnerability to effectively steal session cookies of privileged logged on users.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.