vendor:
Genialcloud ProJ
by:
Andrea Intilangelo
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Genialcloud ProJ
Affected Version From: 10
Affected Version To: 10
Patch Exists: YES
Related CWE: CVE-2022-29296
CPE: a:avantune:genialcloud_proj:10
Platforms Tested: Latest Version of Desktop Web Browsers (ATTOW: Firefox 100.0, Microsoft Edge 101.0.1210.39)
2022
Avantune Genialcloud ProJ 10 – Cross-Site Scripting (XSS)
Reflected Cross-Site Scripting (XSS) vulnerability in login-portal webpage of Genialcloud ProJ (and potentially in other platforms from the same software house "Avantune" since codebase seems shared with their other products: Facsys and Analysis) allows remote attacker to inject and execute arbitrary web scripts or HTML via a crafted payload. Request parameters affected is "msg".
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.