Cross-Site Scripting Vulnerability in Veeam ONE Reporter by Veeam Software
CVE-2019-14297
5.4MEDIUM
What is CVE-2019-14297?
A Cross-Site Scripting vulnerability in Veeam ONE Reporter 9.5.0.3201 allows attackers to exploit the Add/Edit Widget feature by inserting a crafted Caption field in the setDashboardWidget function within CommonDataHandlerReadOnly.ashx. This flaw can potentially lead to unauthorized script execution in the user's browser, putting sensitive data at risk.