IBM Datacap 9.1.7, 9.1.8 i 9.1.9 oraz IBM Datacap Navigator 9.1.7, 9.1.8 i 9.1.9 są podatne na XSS. Ta luka pozwala niezauwierzytelnemu atakującemu osadzić dowolny kod JavaScript w interfejsie Web UI, zmieniając zamierzoną funkcjonalność i potencjalnie prowadząc do ujawnienia poświadczeń w zaufanej sesji.
▸ Pokaż oryginał (EN)
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:LIBM Datacap
APPIbm9.1.79.1.89.1.9IBM Datacap Navigator
APPIbm9.1.79.1.89.1.9
Powiązane podatności
IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker...
IBM Datacap w wersjach 9.1.7, 9.1.8 i 9.1.9 oraz IBM Datacap Navigator w wersjach 9.1.7, 9.1.8 i 9.1.9 pozwala...
IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of t...
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session coo...
IBM Datacap 9.1.7, 9.1.8, and 9.1.9 could allow a remote attacker to hijack the clicking action of the vic...