Assigner: | TR-CERT |
Reserved: | 2024-05-10 |
Published: | 2024-06-24 |
Updated: | 2024-06-24 |
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
6.6.4.4 before 6.6.4.5
Credits
Ertuğrul KUZGUN
References
https://www.usom.gov.tr/bildirim/tr-24-0739