vendor:
Vicidial
by:
David Silveiro
7.5
CVSS
HIGH
Authenticated Stored XSS
79
CWE
Product Name: Vicidial
Affected Version From: 2.11
Affected Version To: 2.11
Patch Exists: NO
Related CWE:
CPE: a:vicidial_project:vicidial:2.11
Platforms Tested:
0 day
Vicidial 2.11 Scripts – Authenticated Stored XSS
The vulnerability is triggered when an authenticated user with sufficient permissions creates a script without sufficient sanitization happening within 'Script Name' and 'Script Text'. This can be used to infect other hosts on the network.
Mitigation:
Implement proper input sanitization and validation to prevent the execution of malicious scripts.