vendor:
Secret Server
by:
Marco Delai
7.5
CVSS
HIGH
XSS
79
CWE
Product Name: Secret Server
Affected Version From: 8.6.2000
Affected Version To: 8.8.2004
Patch Exists: YES
Related CWE: CVE-2015-3443
CPE: a:thycotic:secret_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Stored Cross-Site Scripting Vulnerability (XSS)
The identified vulnerability (stored Cross-Site Scripting) allows the execution of JavaScript code in the browser of a valid user when it toggle the password mask on a specially crafted password. This allows, for example, an attacker to prepare a specially crafted shared password, which when read by another user, can steal all other passwords the victim has access to.
Mitigation:
Thycotic Secret Server customers should upgrade to version 8.8.000005 or later.