TAIWAN-CA(TWCA) JCICSecurityTool's Registry-related functions have insufficient filtering for special characters. An unauthenticated remote attacker can inject malicious script into a webpage to perform XSS (Stored Cross-Site Scripting) attack.
References
| Link | Resource |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7602-a47a2-1.html | Third Party Advisory |
Configurations
Information
Published : 2023-12-15 09:15
Updated : 2023-12-22 15:19
NVD link : CVE-2023-48387
Mitre link : CVE-2023-48387
JSON object : View
Products Affected
twca
- jcicsecuritytool
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
