Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Reflected XSS. This issue affects Panel: before v2.3.24.
The vulnerability results from improper neutralization of input data during webpage generation (CWE-79). An attacker can deliver a crafted payload in an HTTP request, which is reflected by the server and embedded in the response without proper encoding or filtering. The victim must be tricked into clicking a malicious link or visiting a crafted URL, which causes JavaScript code to be executed in their browser in the context of the trusted application domain.
An attacker can hijack the session of a logged-in user, steal sensitive data (e.g., session cookies, tokens), perform actions on behalf of the victim, or conduct further attacks on the infrastructure managed by the Panel. Due to high impact ratings on dependent systems (SC:H, SI:H, SA:H), the consequences may extend beyond the end user themselves.
Eliz Software Panel should be updated to version v2.3.24 or newer. Detailed information regarding the patch is available in the vendor's references and in the USOM security notice (TR-24-1497).
Eliz Software Panel in versions before v2.3.24.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XElizsoftware Panel
APPElizsoftware< 2.3.24
Related vulnerabilities
SQL Injection umożliwiający wykonanie poleceń w Eliz Software Panel
Stored XSS w Eliz Software Panel — wstrzyknięcie skryptu po stronie serwera
Przechowywanie haseł w postaci jawnej w Elizsoftware Panel