SearchBlox product with version before 9.2.1 is vulnerable to stored cross-site scripting at multiple user input parameters. In SearchBlox products multiple parameters are not sanitized/validate properly which allows an attacker to inject malicious JavaScript.
References
Link | Resource |
---|---|
https://developer.searchblox.com/v9.2/changelog/version-921 | Release Notes |
Configurations
History
No history.
Information
Published : 2023-09-05 20:15
Updated : 2023-11-07 03:14
NVD link : CVE-2020-10128
Mitre link : CVE-2020-10128
CVE.ORG link : CVE-2020-10128
JSON object : View
Products Affected
searchblox
- searchblox
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')