Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN32504719/index.html | vdb entry third party advisory |
http://www.securityfocus.com/bid/93477 | vdb entry third party advisory |
http://jvndb.jvn.jp/en/contents/2016/JVNDB-2016-000202.html | vdb entry third party advisory |