In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's browser via logon.jsp?logon_error= on the login screen of the Web application.
References
Link | Resource |
---|---|
https://www.edifecs.com/services/managed-services/ | Vendor Advisory |
https://gist.github.com/rvismit/c2da674254f53c40d3a9eb3896277ebc | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-07-12 09:15
Updated : 2021-07-14 12:45
NVD link : CVE-2021-36381
Mitre link : CVE-2021-36381
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
edifecs
- transaction_management