Required CVE Record Information
Description
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to send a crafted URL for XSS.
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- https://gist.github.com/barrett092/c70752ca6960b8b9616a03006f291a28 x_transferred
- https://docs.emssoftware.com/Content/V44.1_ReleaseNotes.htm x_transferred
- securityfocus.com: 104428 vdb-entryx_transferred
- exploit-db.com: 44831 exploitx_transferred