Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://docs.google.com/document/d/1dJP1CQupHGXjsMWthgPGepOkcnxYA4mDfdjOE46nrhM/edit?usp=sharing x_transferred
- exploit-db.com: 45053 exploitx_transferred