vendor:
Sentrifugo
by:
creosote
5.4
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Sentrifugo
Affected Version From: 3.2
Affected Version To: 3.2
Patch Exists: YES
Related CWE: CVE-2019-15814
CPE: a:sentrifugo:sentrifugo:3.2
Platforms Tested: Ubuntu 18.04
2019
Sentrifugo 3.2 – Persistent Cross-Site Scripting
Multiple Stored XSS vulnerabilities were found in Sentrifugo 3.2. In most test cases session riding was also possible by utilizing the XSS vulnerability. This potentially allows for full account takeover.
Mitigation:
Implement input validation and output encoding to prevent XSS attacks.