Cross Site Scripting esiste in InfoVista VistaPortal SE versione 5.1 (accumulo 51029). La pagina ""EditCurrentPresentSpace.jsp"" ha riflesso XSS tramite i parametri ConnPoolName, GrouplD e ParentID. |
http://seclists.org/fulldisclosure/2018/Dec/20 http://packetstormsecurity.com/files/150690/VistaPortal-SE-5.1-Cross-Site-Scripting.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19765 |
Vulnerabilità: CVE-2018-19765
