vendor:
Open-AudIT
by:
Ranjeet Jaiswal
6.1
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Open-AudIT
Affected Version From: 2.2.6
Affected Version To: 2.2.6
Patch Exists: YES
Related CWE: CVE-2018-14493
CPE: 2.2.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
Open-AudIT Community 2.2.6 – Cross-Site Scripting
Cross-site scripting (XSS) vulnerability on Groups Page in Open-AudIT Community edition in 2.2.6 allows remote attackers to inject arbitrary web script or HTML in group name, as demonstrated in the Proof of Concept.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.