We found results for “”
WS-2019-0134
Good to know:
Date: June 4, 2019
ids-enterprise has a Cross-Site Scripting vulnerability in versions before 4.18.2 due to failure of the The modal component to sanitize nput to the title attribute, which may allow attackers to execute arbitrary JavaScript.
Language: JS
Severity Score
Severity Score
Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |