vendor:
Protege GX/WX
by:
LiquidWorm
8.8
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Protege GX/WX
Affected Version From: GX: Ver: 2.08.1002 K1B3 Lib: 04.00.217 Int: 2.3.235.J013 OS: 2.0.20 WX: Ver: 4.00 284 H062 App: 02.08.766 Lib: 04.00.169 Int: 02.2.208
Affected Version To: GX: Ver: 2.08.1002 K1B3 Lib: 04.00.217 Int: 2.3.235.J013 OS: 2.0.20 WX: Ver: 4.00 284 H062 App: 02.08.766 Lib: 04.00.169 Int: 02.2.208
Patch Exists: NO
Related CWE:
CPE: a:ict:protege_gx:2.08.1002_k1b3
Platforms Tested: Microsoft-WinCE/6.00
2022
ICT Protege GX/WX 2.08 โ Stored Cross-Site Scripting (XSS)
The application suffers from an authenticated stored XSS vulnerability. The issue is triggered when input passed to the 'Name' parameter is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Mitigation:
Input validation should be used to ensure that untrusted data is not stored in the application.