Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Besnardf

#42565de 53,624
6.3CVSS total
Vulnerabilidades · 1
PT-2023-25875
6.3
2023-07-13
Unknown · Joc Cockpit · CVE-2023-37272
**Name of the Vulnerable Software and Affected Versions** JobScheduler (JS1) versions 1.13.0 through 1.13.18 **Description** The issue allows for an XSS attack through specifically crafted file names when uploading files for user-generated documentation in JOC Cockpit. This can inject code that is executed by the browser. The risk of this issue is considered high. **Recommendations** For JobScheduler (JS1) versions 1.13.0 through 1.13.18, update to version 1.13.19 to resolve the issue.