A Remote Cross-Site Scripting (XSS) vulnerability in HPE LoadRunner v12.53 and earlier and HPE Performance Center version v12.53 and earlier was found.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://www.securitytracker.com/id/1038868 | third party advisory vdb entry |
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03764en_us | vendor advisory |
http://www.securitytracker.com/id/1038867 | third party advisory vdb entry |