Advisory ID | NN-2020:3-01 |
---|---|
Topic | Angular template injection on custom report name field |
CWE Impact | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Issue date | 2020-05-26 |
Affects | Guardian, CMC < v20.0.3 |
CVE Name(s) | NA |
CVSS Details | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
CVSS Score | 4.6 (CVSS v4.0) 4.8 (CVSS v3.1) |
CVE Risk Level | Medium (CVSS v4.0) Medium (CVSS v3.1) |
Risk Level for Nozomi customers | Low |
Report name field is affected by angular template injection which can lead to XSS attacks.
Custom report name field can lead to XSS attacks by malicious users. The attacker must have a valid Guardian/CMC login with the ‘Report editor’ capability to leverage this.
Guardian, CMC < v20.0.3
None
v19 series: Upgrade to v19.0.11 v20 series: Upgrade to v20.0.3
We thank the following parties for their efforts: