Feedback.asp in Xiao5uCompany 1.7 has XSS because the XSS protection mechanism in Safe.asp is insufficient (for example, it considers SCRIPT and IMG elements, but does not consider VIDEO elements).
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-07-23T08:00:00

Updated: 2018-07-23T07:57:01

Reserved: 2018-07-22T00:00:00


Link: CVE-2018-14527

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-07-23T08:29:00.653

Modified: 2018-09-18T18:36:54.007


Link: CVE-2018-14527

JSON object: View

cve-icon Redhat Information

No data.

CWE