SysJust Syuan-Gu-Da-Shih, versions before 20191223, contain vulnerability of Cross-Site Scripting(XSS), personal information may be leaked to attackers via the vulnerability.
Solution:
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://tvn.twcert.org.tw/taiwanvn/TVN-201910015 | third party advisory |
https://www.chtsecurity.com/news/a791f509-9782-4be1-b71f-22fc619f8215 | third party advisory |