CVE-2020-29030 – Insufficient CSRF guards
https://notcve.org/view.php?id=CVE-2020-29030
Cross-Site Request Forgery (CSRF) vulnerability in web GUI of Secomea GateManager allows an attacker to execute malicious code. This issue affects: Secomea GateManager All versions prior to 9.4. Una vulnerabilidad de tipo Cross-Site Request Forgery (CSRF) en la GUI web de Secomea GateManager, permite a un atacante ejecutar código malicioso. Este problema afecta a: Secomea GateManager Todas las versiones anteriores a 9.4 • https://www.secomea.com/support/cybersecurity-advisory • CWE-352: Cross-Site Request Forgery (CSRF) •
CVE-2020-29028 – Reflected XSS issues
https://notcve.org/view.php?id=CVE-2020-29028
Cross-site Scripting (XSS) vulnerability in web GUI of Secomea GateManager allows an attacker to inject arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4. Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en la GUI web de Secomea GateManager, permite a un atacante inyectar código javascript arbitrario. Este problema afecta a: Secomea GateManager todas las versiones anteriores a 9.4 • https://www.secomea.com/support/cybersecurity-advisory • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2020-29029 – XSS issue due to insufficient sanitization of input field
https://notcve.org/view.php?id=CVE-2020-29029
Improper Input Validation, Cross-site Scripting (XSS) vulnerability in Web GUI of Secomea GateManager allows an attacker to execute arbitrary javascript code. This issue affects: Secomea GateManager all versions prior to 9.4. Una vulnerabilidad de Comprobación Inapropiada de la Entrada y de tipo Cross-site Scripting (XSS) en la GUI web de Secomea GateManager, permite a un atacante ejecutar código javascript arbitrario. Este problema afecta a: Secomea GateManager todas las versiones anteriores a 9.4 • https://www.secomea.com/support/cybersecurity-advisory • CWE-20: Improper Input Validation CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •