Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies to the search functionality for the searchKey parameter.
References
Link | Resource |
---|---|
https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=42 | Exploit Third Party Advisory |
https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=42 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 04:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.hacktivesecurity.com/index.php?controller=post&action=view&id_post=42 - Exploit, Third Party Advisory |
Information
Published : 2019-10-30 19:15
Updated : 2024-11-21 04:32
NVD link : CVE-2019-18205
Mitre link : CVE-2019-18205
CVE.ORG link : CVE-2019-18205
JSON object : View
Products Affected
zucchetti
- infobusiness
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')