Stored XSS Vulnerability in Ericsson BSCS iX R18 Billing & Rating Module
CVE-2020-29145

5.4MEDIUM

What is CVE-2020-29145?

The web-based ADMX module in Ericsson BSCS iX R18 is susceptible to a stored XSS vulnerability via the name or description fields, specifically within the solutionUnitServlet?SuName=UserReferenceDataSU Access Rights Group. This flaw enables an attacker to potentially hijack user sessions, facilitating account takeover and endanger the security of administrators' browsers through exploitation techniques utilizing frameworks like BeEF.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.