A Reflected cross-site scripting (XSS) vulnerability in "ccHandler.aspx" CADClick <= 1.11.0 allows remote attackers to inject arbitrary web script or HTML via the "bomid" parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://cadclick.de/ | product |
http://kimweb.de/ | product |
https://piuswalter.de/blog/multiple-critical-vulnerabilities-in-cadclick/ | exploit third party advisory |