NN-2020:3-01

Angular template injection on custom report name field

Last update: 2024-05-20

Advisory IDNN-2020:3-01
TopicAngular template injection on custom report name field
CWE ImpactCWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Issue date2020-05-26
AffectsGuardian, CMC < v20.0.3
CVE Name(s)NA
CVSS DetailsCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS Score4.6 (CVSS v4.0)
4.8 (CVSS v3.1)
CVE Risk LevelMedium (CVSS v4.0)
Medium (CVSS v3.1)
Risk Level for Nozomi customersLow

Summary

Report name field is affected by angular template injection which can lead to XSS attacks.

Impact

Custom report name field can lead to XSS attacks by malicious users. The attacker must have a valid Guardian/CMC login with the ‘Report editor’ capability to leverage this.

Affected Products

Guardian, CMC < v20.0.3

Workarounds and Mitigations

None

Solutions

v19 series: Upgrade to v19.0.11 v20 series: Upgrade to v20.0.3

Modification History

2020-05-26: Initial revision
2023-09-04: Minor updates to format and metadata to improve the CSAF implementation
2023-11-13: Migrated to CSAF VEX format
2023-11-16: CSAF vers improvements
2024-05-20: Added CVSS v4.0 scoring where applicable

Related Links

Acknowledgements

We thank the following parties for their efforts:

  • Schneider Electric Industry Services for finding this bug

Contact

Nozomi Networks Product Security team can be reached at prodsec@nozominetworks.com.
More contact details on the PSIRT page.