vendor:
enteliTOUCH
by:
LiquidWorm
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: enteliTOUCH
Affected Version From: 3.40.3935
Affected Version To: 3.33.4005
Patch Exists: NO
Related CWE:
CPE: delta_controls:enteliTOUCH
Platforms Tested: DELTA enteliTOUCH
2022
Delta Controls enteliTOUCH 3.40.3935 – Cross-Site Scripting (XSS)
Input passed to the POST parameter 'Username' is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site.
Mitigation:
Input validation should be performed to ensure that untrusted data is not used to update a web page.