vendor:
vxAG and vAPV Appliances
by:
xistence
7,5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: vxAG and vAPV Appliances
Affected Version From: 9.2.0.34
Affected Version To: 8.3.2.17
Patch Exists: Yes
Related CWE: N/A
CPE: a:array_networks:vxag:9.2.0.34
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
Array Networks vxAG and vAPV Appliances XSS Vulnerability
The vulnerability exists due to insufficient sanitization of user-supplied input in the web interface of the affected appliances. A remote attacker can execute arbitrary HTML and script code in a user's browser session in context of an affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks.
Mitigation:
Ensure that user-supplied input is properly sanitized before being used in the web interface.