Vulnerability CVE-2022-39172


Published: 2023-10-30   Modified: 2023-10-31

Description:
A stored XSS in the process overview (bersicht zugewiesener Vorgaenge) in mbsupport openVIVA c2 20220101 allows a remote, authenticated, low-privileged attacker to execute arbitrary code in the victim's browser via name field of a process.

See advisories in our WLB2 database:
Topic
Author
Date
Low
openVIVA c2 20220101 Cross Site Scripting
Daniel Hirschber...
03.10.2023

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://sec-consult.com/vulnerability-lab/advisory/stored-cross-site-scripting-in-mb-support-broker-management-solution-openviva-c2/

Copyright 2024, cxsecurity.com

 

Back to Top