vendor:
Open-AudIT Community
by:
Dominic Clark (parzival)
6.1
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Open-AudIT Community
Affected Version From: <= 4.2.0
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2021-44916
CPE: a:opmantek:open-audit:4.2.0
Platforms Tested: Windows 10
2021
Open-AudIT Community 4.2.0 – Cross-Site Scripting (XSS) (Authenticated)
There is an issue with link creation in the GUI with Open-AudIT Community. If a bad value is passed to the routine via a URL, javascript code can be executed. This requires the user be logged in to Open-AudIT Community to trigger.
Mitigation:
Apply the recommended workarounds and mitigations provided by Opmantek.