Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Eliz Software Panel allows Stored XSS. This issue affects Panel: before v2.3.24.
The Eliz Software Panel application improperly neutralizes input data before displaying it on web pages. An attacker with at least regular user privileges can save a malicious JavaScript payload in data stored by the application. Any user who subsequently opens the page containing this payload will unknowingly execute the embedded script in their browser context. The vulnerability is of Stored XSS type — this means the malicious code is permanently stored on the server side and does not require the attacker to deliver it each time.
An attacker can hijack sessions of other users (including administrators), perform actions on their behalf, steal authentication credentials, and modify application content. High impact on confidentiality, integrity, and availability in both direct systems and related contexts indicates potential serious consequences for the entire application environment.
Eliz Software Panel must be immediately updated to version v2.3.24 or later. Detailed information is available in the manufacturer's references and the USOM security bulletin (TR-24-1497).
Eliz Software Panel in versions earlier than v2.3.24.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XElizsoftware Panel
APPElizsoftware< 2.3.24
Related vulnerabilities
SQL Injection umożliwiający wykonanie poleceń w Eliz Software Panel
Przechowywanie haseł w postaci jawnej w Elizsoftware Panel
Reflected XSS w Eliz Software Panel przed wersją v2.3.24