Erxes vulnerable to Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
Feb 21, 2023
to the GitHub Advisory Database
•
Updated Feb 22, 2023
Description
Published by the National Vulnerability Database
Feb 20, 2023
Published to the GitHub Advisory Database
Feb 21, 2023
Reviewed
Feb 22, 2023
Last updated
Feb 22, 2023
Erxes, an experience operating system (XOS) with a set of plugins, is vulnerable to cross-site scripting in all versions. This results in client-side code execution. The victim must follow a malicious link or be redirected there from malicious web site. There are no known patches.
References