The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://mattschmidt.net/2020/11/10/dundas-persistent-xss/ | third party advisory exploit |