RemObjects Remoting SDK 9 1.0.0.0 for Delphi is vulnerable to a reflected Cross Site Scripting (XSS) attack via the service parameter to the /soap URI, triggering an invalid attempt to generate WSDL.
References
Link | Resource |
---|---|
https://talk.remobjects.com/t/reflected-cross-site-scripting-xss-vulnerability/14662 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2017-11-08 17:29
Updated : 2024-02-28 16:04
NVD link : CVE-2017-16665
Mitre link : CVE-2017-16665
CVE.ORG link : CVE-2017-16665
JSON object : View
Products Affected
remobjects
- remoting_sdk_9
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')