CVE-2018-14875

An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter.
Configurations

Configuration 1 (hide)

cpe:2.3:a:polarisft:intellect_core_banking:9.7.1:*:*:*:*:*:*:*

History

21 Nov 2024, 03:49

Type Values Removed Values Added
References () https://neetech18.blogspot.com/2019/03/reflected-xss-vulnerability-in-polaris.html - Exploit, Third Party Advisory () https://neetech18.blogspot.com/2019/03/reflected-xss-vulnerability-in-polaris.html - Exploit, Third Party Advisory

Information

Published : 2019-04-30 19:29

Updated : 2024-11-21 03:49


NVD link : CVE-2018-14875

Mitre link : CVE-2018-14875

CVE.ORG link : CVE-2018-14875


JSON object : View

Products Affected

polarisft

  • intellect_core_banking
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')