vendor:
Enterprise Asset Management
by:
N/A
5,4
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: Enterprise Asset Management
Affected Version From: V11.0 Build 201410
Affected Version To: V11.0 Build 201410
Patch Exists: YES
Related CWE: CVE-2017-7953
CPE: a:infor:enterprise_asset_management
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Stored XSS in INFOR EAM V11.0 Build 201410 via comment fields
An authenticated user could become a valid victim to the described attack by navigating to the infected page. The comment visualization triggers injected javascript code. On the other side any user able to write a comment could become a possible attacker by introducing javascript into the comment body.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.