Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS).
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://midas.psi.ch/elog/download/ChangeLog | |
http://osvdb.org/41685 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/40124 | vdb entry |
http://www.securityfocus.com/bid/27526 | patch vdb entry |