Stored cross-site scripting vulnerability in View setting page of VI Web Client prior to 7.9.6 allows a remote authenticated attacker to inject an arbitrary script.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://downloadvi.com/downloads/IPServer/v7.9/796232/v796232RN.pdf | release notes |
https://jvn.jp/en/jp/JVN60140221/ | third party advisory |