Unauthenticated Reflected Cross-Site Scripting in Computrols CBAS
CVE-2019-10846
6.1MEDIUM
What is CVE-2019-10846?
Computrols CBAS version 18.0.0 is susceptible to unauthenticated reflected cross-site scripting vulnerabilities. This issue arises in the login and password reset pages, where an attacker can exploit the username parameter via GET requests. If successful, this could allow unauthorized users to execute malicious scripts in the context of the victims' browsers, potentially leading to theft of sensitive information such as session cookies or credentials.
