VulnerabilityModified
CVE-2019-20221
In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS.
MEDIUM 6.1EPSS 0.67%
Does this matter?
Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.
Description
In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sitracker/support incident tracker
- Source
- cve@mitre.org
References
- https://fatihhcelik.blogspot.com/2019/12/support-incident-tracker-xss-in-plugin.htmlExploit, Third Party Advisory
- https://fatihhcelik.blogspot.com/2019/12/support-incident-tracker-xss-in-plugin.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.