An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.
The XSS class vulnerability (CWE-79) consists of the ability to inject and execute malicious JavaScript code in the context of the victim's browser. The attack vector indicates that user interaction (UI:R) is required to carry out the attack, while the attack originates from a remote location over the network (AV:N) without the need for privileges (PR:N). Due to the changed scope (S:C), the effects of the attack extend beyond the application being the direct target, potentially threatening associated resources.
An attacker can hijack the session of a logged-in DriveLock Operations Center user, thereby gaining access to system data and functions with the victim's privilege level. Consequences include high loss of data confidentiality and integrity as well as partial threat to system availability.
DriveLock should be updated to version 25.1.5 or newer, in which the bug has been fixed. Details are available in the manufacturer's security bulletin (Security Bulletin 25-002) at the address indicated in the references.
DriveLock in versions from 25.1.2 to 25.1.4 (before version 25.1.5) — DriveLock Operations Center component.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:LDrivelock
APPDrivelock25.1.225.1.4
Related vulnerabilities
DriveLock — obejście uwierzytelniania agenta (Auth Bypass) w DES
DriveLock — eskalacja uprawnień przez manipulację procesami uprzywilejowanymi
DriveLock — nieautoryzowana eskalacja uprawnień do roli Supervisor przez API
DriveLock — privilege escalation umożliwiające przejęcie kontroli nad systemem
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. An unpriv...