Vulnerability CVE-2021-31583


Published: 2021-04-23

Description:
Sipwise C5 NGCP CSC through CE_m39.3.1 has multiple authenticated stored and reflected XSS vulnerabilities when input passed via several parameters to several scripts is not properly sanitized before being returned to the user: Stored XSS in callforward/time/set/save (POST tsetname); Reflected XSS in addressbook (GET filter); Stored XSS in addressbook/save (POST firstname, lastname, company); and Reflected XSS in statistics/versions (GET lang).

See advisories in our WLB2 database:
Topic
Author
Date
Low
Sipwise C5 NGCP CSC Cross Site Scripting
LiquidWorm
23.04.2021

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
http://packetstormsecurity.com/files/162316/Sipwise-C5-NGCP-CSC-Cross-Site-Scripting.html
https://www.zeroscience.mk/en/vulnerabilities
https://www.sipwise.com

Copyright 2024, cxsecurity.com

 

Back to Top