SOLDR (System of Orchestration, Lifecycle control, Detection and Response) 1.1.0 allows stored XSS via the module editor.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/vxcontrol/soldr/compare/v1.1.0...v1.2.0 | release notes |
https://github.com/vxcontrol/soldr/issues/89 | third party advisory issue tracking exploit |