vendor:
e-Library
by:
Özkan Mustafa Akkus (AkkuS)
6.1
CVSS
MEDIUM
Cross-Site Scripting
CWE
Product Name: e-Library
Affected Version From: 3.5.x
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2018-20503
CPE:
Platforms Tested: Firefox/52 and Chrome/69
2019
SirsiDynix e-Library <= 3.5.x - Cross-Site Scripting
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.