Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://spiceworks.com | vendor advisory |
https://abuyv.com | third party advisory |
https://abuyv.com/cve/spiceworks-stored-xss | third party advisory exploit |