Gazie 7.29 is affected by: Cross Site Scripting (XSS) via http://192.168.100.7/gazie/modules/config/admin_utente.php?user_name=amministratore&Update. An attacker can inject JavaScript code, and the webapplication stores the injected code.
References
Link | Resource |
---|---|
http://gazie.com | Broken Link |
http://gazie.devincentiis.it/ | Vendor Advisory |
https://github.com/Gr3gPr1est/BugReport/blob/master/CVE-2020-21731 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-09-14T11:45:40
Updated: 2020-09-14T11:45:40
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-21731
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-09-14T12:15:10.773
Modified: 2020-09-17T16:06:13.163
Link: CVE-2020-21731
JSON object: View
Redhat Information
No data.
CWE