Cross-Site Scripting Vulnerability in Kaspersky Anti-Virus for Linux File Server
CVE-2017-9813
6.1MEDIUM
What is CVE-2017-9813?
In Kaspersky Anti-Virus for Linux File Server prior to Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the 'scriptName' parameter of the 'licenseKeyInfo' action method is susceptible to cross-site scripting attacks. This vulnerability may allow unauthorized users to inject arbitrary JavaScript code into web pages viewed by legitimate users, potentially compromising sensitive data and leading to unauthorized actions within the application. Proper input validation and sanitization measures should be implemented to mitigate this risk.