Cross-Site Scripting Flaw in Greenbone Security Assistant by Greenbone
CVE-2016-1926
6.1MEDIUM
Key Information:
- Vendor
Greenbone
- Vendor
- CVE Published:
- 26 January 2016
What is CVE-2016-1926?
The Greenbone Security Assistant (GSA) version 6.x prior to 6.0.8 contains a cross-site scripting vulnerability in its charts module. This flaw permits remote attackers to execute arbitrary web scripts or HTML by manipulating the aggregate_type parameter within a get_aggregate command to the Open Management Protocol (OMP). Successful exploitation could lead to unauthorized actions being performed in the context of the user’s session, potentially compromising sensitive information.
