Cross-Site Scripting Vulnerability in Flexense DiskBoss Enterprise
CVE-2018-10294
6.1MEDIUM
What is CVE-2018-10294?
Flexense DiskBoss Enterprise versions 7.4.28 through 9.1.16 are vulnerable to a Cross-Site Scripting (XSS) attack. This vulnerability allows malicious users to inject arbitrary web scripts into the affected application. When a user accesses a compromised page, their browser could execute those scripts with the same permissions as the user, potentially compromising sensitive information and site functionality. Administrators of DiskBoss Enterprise should prioritize updating to the latest version to mitigate this risk.