Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the RIA IT or the Fleet role can create a crafted work order in the damage reports section (or change existing work orders). The XSS payload is in the work order number.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/165278/Sofico-Miles-RIA-2020.2-Build-127964T-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
https://www.sofico.global | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2021-12-15 07:15
Updated : 2021-12-17 20:42
NVD link : CVE-2021-41557
Mitre link : CVE-2021-41557
CVE.ORG link : CVE-2021-41557
JSON object : View
Products Affected
sofico
- miles_rich_internet_application
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')