vendor:
Hipergate
by:
Nahuel Grisolía
4.3
CVSS
MEDIUM
Permanent Cross-Site Scripting (XSS)
79
CWE
Product Name: Hipergate
Affected Version From: Hipergate 4.0.12
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: Unknown
Platforms Tested: Multiple
2010
Permanent Cross-Site Scripting (XSS) in Hipergate 4.0.12
A permanent Cross Site Scripting vulnerability was found in Hipergate 4.0.12, because the application fails to sanitize user-supplied input. Any logged-in user who is able to add a New Campaign can trigger the vulnerability.
Mitigation:
Unknown