Cross Site Scripting esiste in InfoVista VistaPortal SE versione 5.1 (accumulo 51029). La pagina ""EditCurrentUser.jsp"" ha riflesso XSS tramite i parametri GroupID e ConnPoolName. |
http://seclists.org/fulldisclosure/2018/Dec/20 http://packetstormsecurity.com/files/150690/VistaPortal-SE-5.1-Cross-Site-Scripting.html https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19773 |
Vulnerabilità: CVE-2018-19773
