vendor:
CaseAware
by:
justpentest
6,1
CVSS
MEDIUM
Reflected Cross Site Scripting
79
CWE
Product Name: CaseAware
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: YES
Related CWE: CVE-2017-5631
CPE: a:kmcis:caseaware
Metasploit:
N/A
Other Scripts:
N/A
Tags: edb,cve,cve2017,xss,caseaware
CVSS Metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Nuclei Metadata: {'max-request': 1, 'vendor': 'kmc_information_systems', 'product': 'caseaware'}
Platforms Tested: None
2017
CaseAware Cross Site Scripting Vulnerability
KMCIS CaseAware contains a reflected cross-site scripting vulnerability via the user parameter transmitted in the login.php query string.
Mitigation:
Input sanitization should be implemented to prevent XSS attacks.