CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.
References
Link Resource
http://seclists.org/fulldisclosure/2018/Jun/45 Mailing List Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-06-20T15:00:00

Updated: 2018-06-20T14:57:01

Reserved: 2018-03-26T00:00:00


Link: CVE-2018-9036

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-06-20T15:29:00.247

Modified: 2018-08-10T13:57:06.573


Link: CVE-2018-9036

JSON object: View

cve-icon Redhat Information

No data.

CWE