vendor:
CloudShell
by:
Benjamin Lee
5,4
CVSS
MEDIUM
Cross Site Scripting
79
CWE
Product Name: CloudShell
Affected Version From: v7.1.0.6508 (Patch 6)
Affected Version To: v7.1.0.6508 (Patch 6)
Patch Exists: YES
Related CWE: CVE-2017-9767
CPE: qualicloudshell
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Multiple Stored Cross Site Scripting
Quali CloudShell (v7.1.0.6508 Patch 6) is vulnerable to multiple stored XSS vulnerabilities on its platform this can be exploited to execute arbitrary HTML and script code on all users (including administrators) from a low-privileged account.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.