Newcomer1989 TSN-Ranksystem Dok 1.2.6 webinterface/bot.php getlog Skriptovanje preko sajta

Pronađena je ranjivost klasifikovana kao Problematiиno u Newcomer1989 TSN-Ranksystem Dok 1.2.6. Zahvaćeno je funkcija getlog u fajlu webinterface/bot.php. Izmena rezultira Skriptovanje preko sajta. Definisanje problema putem CWE vodi do CWE-79. Ova slabost je objavljena 01/11/2023 kao 467. Obaveštenje možete preuzeti sa github.com. Ova ranjivost je registrovana kao CVE-2018-25073. Napad se može izvesti na daljinu. Napad je moguć samo unutar lokalne mreže. Postoje tehnički detalji. Експлоит није доступан. Trenutno je cena za eksploataciju približno USD $0-$5k u ovom momentu. Projekat MITRE ATT&CK označava tehniku napada kao T1059.007. Klasifikovano je kao nije definisano. Kao 0-day, procenjuje se da je cena na ilegalnom tržištu bila oko $0-$5k. Ažuriranjem na verziju 1.2.7 moguće je otkloniti ovaj problem. Preuzmite najnoviju verziju na github.com. Naziv zakrpe je b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77. Zakrpa može biti preuzeta sa github.com. Savetuje se nadogradnja ugrožene komponente. Once again VulDB remains the best source for vulnerability data.

3 Promene · 75 Tačke podataka

PoljeKreirali
01/11/2023 14:59
Ažurira 1/2
02/01/2023 15:45
Ažurira 2/2
02/01/2023 15:51
software_vendorNewcomer1989Newcomer1989Newcomer1989
software_nameTSN-RanksystemTSN-RanksystemTSN-Ranksystem
software_version<=1.2.6<=1.2.6<=1.2.6
software_filewebinterface/bot.phpwebinterface/bot.phpwebinterface/bot.php
software_functiongetloggetloggetlog
vulnerability_cweCWE-79 (Skriptovanje preko sajta)CWE-79 (Skriptovanje preko sajta)CWE-79 (Skriptovanje preko sajta)
vulnerability_risk111
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_uiRRR
cvss3_vuldb_sUUU
cvss3_vuldb_cNNN
cvss3_vuldb_iLLL
cvss3_vuldb_aNNN
cvss3_vuldb_rlOOO
cvss3_vuldb_rcCCC
advisory_identifier467467467
advisory_urlhttps://github.com/Newcomer1989/TSN-Ranksystem/pull/467https://github.com/Newcomer1989/TSN-Ranksystem/pull/467https://github.com/Newcomer1989/TSN-Ranksystem/pull/467
countermeasure_nameNadogradnjuNadogradnjuNadogradnju
upgrade_version1.2.71.2.71.2.7
countermeasure_upgrade_urlhttps://github.com/Newcomer1989/TSN-Ranksystem/releases/tag/1.2.7https://github.com/Newcomer1989/TSN-Ranksystem/releases/tag/1.2.7https://github.com/Newcomer1989/TSN-Ranksystem/releases/tag/1.2.7
patch_nameb3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77
countermeasure_patch_urlhttps://github.com/Newcomer1989/TSN-Ranksystem/commit/b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77https://github.com/Newcomer1989/TSN-Ranksystem/commit/b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77https://github.com/Newcomer1989/TSN-Ranksystem/commit/b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77
countermeasure_advisoryquoteFix reflected XSS in bot.phpFix reflected XSS in bot.phpFix reflected XSS in bot.php
source_cveCVE-2018-25073CVE-2018-25073CVE-2018-25073
cna_responsibleVulDBVulDBVulDB
advisory_date1673391600 (01/11/2023)1673391600 (01/11/2023)1673391600 (01/11/2023)
cvss2_vuldb_avNNN
cvss2_vuldb_acLLL
cvss2_vuldb_ciNNN
cvss2_vuldb_iiPPP
cvss2_vuldb_aiNNN
cvss2_vuldb_rcCCC
cvss2_vuldb_rlOFOFOF
cvss2_vuldb_auSSS
cvss2_vuldb_eNDNDND
cvss3_vuldb_prLLL
cvss3_vuldb_eXXX
cvss2_vuldb_basescore4.04.04.0
cvss2_vuldb_tempscore3.53.53.5
cvss3_vuldb_basescore3.53.53.5
cvss3_vuldb_tempscore3.43.43.4
cvss3_meta_basescore3.53.54.4
cvss3_meta_tempscore3.43.44.3
price_0day$0-$5k$0-$5k$0-$5k
cve_assigned1673391600 (01/11/2023)1673391600 (01/11/2023)
cve_nvd_summaryA vulnerability has been found in Newcomer1989 TSN-Ranksystem up to 1.2.6 and classified as problematic. This vulnerability affects the function getlog of the file webinterface/bot.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.2.7 is able to address this issue. The name of the patch is b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77. It is recommended to upgrade the affected component. VDB-218002 is the identifier assigned to this vulnerability.A vulnerability has been found in Newcomer1989 TSN-Ranksystem up to 1.2.6 and classified as problematic. This vulnerability affects the function getlog of the file webinterface/bot.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.2.7 is able to address this issue. The name of the patch is b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77. It is recommended to upgrade the affected component. VDB-218002 is the identifier assigned to this vulnerability.
cvss3_nvd_avN
cvss3_nvd_acL
cvss3_nvd_prN
cvss3_nvd_uiR
cvss3_nvd_sC
cvss3_nvd_cL
cvss3_nvd_iL
cvss3_nvd_aN
cvss2_nvd_avN
cvss2_nvd_acL
cvss2_nvd_auS
cvss2_nvd_ciN
cvss2_nvd_iiP
cvss2_nvd_aiN
cvss3_cna_avN
cvss3_cna_acL
cvss3_cna_prL
cvss3_cna_uiR
cvss3_cna_sU
cvss3_cna_cN
cvss3_cna_iL
cvss3_cna_aN
cve_cnaVulDB
cvss2_nvd_basescore4.0
cvss3_nvd_basescore6.1
cvss3_cna_basescore3.5

Are you interested in using VulDB?

Download the whitepaper to learn more about our service!