Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:LRsa Archer
APPRsa6.0 – 6.10.0.4 (excl.)6.11 – 6.11.0.2.4 (excl.)
Related vulnerabilities
RSA Archer – błąd kontroli dostępu w module SSO ADFS (RCE/przejęcie systemu)
RSA Archer — obejście uwierzytelnienia przez niewystarczające dane logowania
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthent...
RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.
RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site script...