Cross-Site Scripting Vulnerability in Open-AudIT Professional by Open-AudIT
CVE-2018-8903
5.4MEDIUM
What is CVE-2018-8903?
Open-AudIT Professional 2.1 is susceptible to a Cross-Site Scripting (XSS) vulnerability that can be exploited through the Name or Description fields on the Credentials screen. An attacker may inject malicious scripts, which could run in the context of another user's session, potentially compromising sensitive information and leading to unauthorized actions on behalf of that user.