Stored and Reflected Cross-Site Scripting in Heimdall Application Dashboard
CVE-2022-47968
5.4MEDIUM
What is CVE-2022-47968?
The Heimdall Application Dashboard, up to version 2.5.4, is susceptible to both reflected and stored Cross-Site Scripting (XSS) attacks. An attacker can exploit this vulnerability by sending specially crafted input via the 'Application name' field on the 'Add application' page. The reflected XSS can compromise a user's session or deliver malicious content. Additionally, the stored XSS can activate when the 'Application list' page is accessed, potentially affecting all users of the application by embedding malicious scripts that execute automatically.
