CVE-2014-8557
13.11.2014, 21:32
Multiple cross-site scripting (XSS) vulnerabilities in JExperts Channel Platform 5.0.33_CCB allow remote attackers to inject arbitrary web script or HTML via the (1) usuario.nome variable in an editarUsuario action to usuario.do or (2) titulo.form variable in a novoChamado action to ticket.do.
Vendor | Product | Version |
---|---|---|
jexperts | channel_platform | 5.0.33_ccb:_ccb |
𝑥
= Vulnerable software versions
References