PT-2018-5323 · J2 Innovations · J2 Innovations Fin Stack
Publicado
2018-07-05
·
Atualizado
2021-04-20
·
CVE-2017-11175
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
J2 Innovations FIN Stack version 4.0
Description
The authentication webform in J2 Innovations FIN Stack is vulnerable to reflected XSS via the query string to the "/login" API endpoint. This issue allows for potential exploitation through malicious queries.
Recommendations
For J2 Innovations FIN Stack version 4.0, as a temporary workaround, consider restricting access to the "/login" API endpoint until a patch is available. Avoid using the query string in the "/login" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
J2 Innovations Fin Stack