PT-2018-5323 · J2 Innovations · J2 Innovations Fin Stack
Published
2018-07-05
·
Updated
2021-04-20
·
CVE-2017-11175
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
J2 Innovations FIN Stack version 4.0
Description
The authentication webform in J2 Innovations FIN Stack is vulnerable to reflected XSS via the query string to the "/login" API endpoint. This issue allows for potential exploitation through malicious queries.
Recommendations
For J2 Innovations FIN Stack version 4.0, as a temporary workaround, consider restricting access to the "/login" API endpoint until a patch is available. Avoid using the query string in the "/login" endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
J2 Innovations Fin Stack