Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to stored XSS. The application reflects previously stored user input without encoding.
References
Link | Resource |
---|---|
http://knowledgebase.serena.com/resources/sites/KNOWLEDGEBASE/content/live/SOLUTIONS/142000/S142001/en_US/sbm_11.7.1_security_bulletin.htm | Patch Release Notes Vendor Advisory |
Configurations
Information
Published : 2021-02-25 20:15
Updated : 2021-03-01 08:16
NVD link : CVE-2019-18942
Mitre link : CVE-2019-18942
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
microfocus
- solutions_business_manager