vendor:
S.A.M.I
by:
LiquidWorm
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: S.A.M.I
Affected Version From: Platform: HAM V1.2 HAM V1.1 HAM V1.0 DINHAM 10W Image Version: 2019.3-20190605144803 2019.2_HP-20190808154634 2018.4_HP-20181015152950 2018.2-20180516100815 2017.2_HP-20180213083050 2013.4_HP-201309301203 AMP Version: 2019.2_HP 2018.4_HP 2017.2_HP 2013.4_HP R20.19.03 R20.18.02 Fix: 2017.2-HP4 2018.4_HP3 2018.5_HP7 2019.2_HP3 2019.3_HP1
Affected Version To: Platform: HAM V1.2 HAM V1.1 HAM V1.0 DINHAM 10W Image Version: 2019.3-20190605144803 2019.2_HP-20190808154634 2018.4_HP-20181015152950 2018.2-20180516100815 2017.2_HP-20180213083050 2013.4_HP-201309301203 AMP Version: 2019.2_HP 2018.4_HP 2017.2_HP 2013.4_HP R20.19.03 R20.18.02 Fix: 2017.2-HP4 2018.4_HP3 2018.5_HP7 2019.2_HP3 2019.3_HP1
Patch Exists: YES
Related CWE: -
CPE: a:fifthplay:s.a.m.i
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
Fifthplay S.A.M.I 2019.2_HP – Persistent Cross-Site Scripting
The application suffers from an unauthenticated stored XSS through POST request. The issue is triggered when input passed via several parameters is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Mitigation:
Upgrade to the latest version of the product.