Security Advisory

CVE-2019-11643

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-05-08 15:26:13
Last updated 2024-08-04 23:03:31
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Persistent XSS has been found in the OneShield Policy (Dragon Core) framework before 5.1.10. Remote adversaries can inject malicious JavaScript into textboxes decorated with type string, which is subsequently stored to the applicable data store. This can be exploited remotely by both authenticated and unauthenticated users.