An issue was discovered in Gentics CMS before 5.43.1. There is stored XSS in the profile description and in the username.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://sec-consult.com/vulnerability-lab/advisory/multiple-vulnerabilies-in-gentics-cms/ | third party advisory exploit |