KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://docs.knime.com/2021-06/server_update_guide/index.html#_bugfixes | release notes vendor advisory |
https://zigrin.com/advisories/knime-server-dom-based-xss-in-a-login-panel/ |