Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Sofico Subscribe
Filtered by product Miles Rich Internet Application
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41557 1 Sofico 1 Miles Rich Internet Application 2021-12-17 3.5 LOW 5.4 MEDIUM
Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a user account of the RIA IT or the Fleet role can create a crafted work order in the damage reports section (or change existing work orders). The XSS payload is in the work order number.