Cross-Site Scripting Vulnerability in Open-AudIT Professional by Open-AudIT
CVE-2018-9155
5.4MEDIUM
What is CVE-2018-9155?
The Cross-Site Scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 enables remote attackers to inject arbitrary web scripts or HTML. This can be executed through crafted component names, particularly within the Admin->Logs and Manage->Attributes sections. Attackers can exploit this vulnerability by manipulating the 'Name (display)' field during the attributes creation process, posing significant security risks for users and their data.