Accusoft PrizmDoc version 13.3 and earlier contains a Stored Cross-Site Scripting issue through a crafted PDF file.
References
Link | Resource |
---|---|
https://medium.com/@mrnikhilsri/stored-cross-site-scripting-in-prizmdoc-13-3-and-before-cve-2018-15546-1938191845c5 | Exploit Third Party Advisory |
http://help.accusoft.com/PrizmDoc/v13.4/ReleaseNotes/index.htm | Release Notes Vendor Advisory |
Configurations
Information
Published : 2018-09-18 14:29
Updated : 2018-11-02 10:23
NVD link : CVE-2018-15546
Mitre link : CVE-2018-15546
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
accusoft
- prizmdoc