PT-2015-7608 · Ntt Data · Ntt Data Smart Sourcing Javascript Module
Published
2015-12-29
·
Updated
2015-12-30
·
CVE-2015-7786
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
NTT DATA Smart Sourcing JavaScript module versions 2003-11-26 through 2013-07-09
Description
The issue is related to a cross-site scripting (XSS) vulnerability. This allows remote attackers to inject arbitrary web script or HTML.
Recommendations
For versions 2003-11-26 through 2013-07-09, consider disabling the JavaScript module until a patch is available. Restrict access to sensitive web pages to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ntt Data Smart Sourcing Javascript Module