ORDAT FOSS-Online before version 2.24.01 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the login page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://foss-online.com | broken link |
http://ordat.com | broken link |
https://mind-bytes.de/cross-site-scripting-in-foss-online-cve-2024-34335/ | exploit technical description |