Description
The web interface in RSA NetWitness 11.7.2.0 allows Cross-Site Scripting (XSS) via the Where textbox on the Reports screen during new rule creation.
References
community.netwitness.com/.../netwitness-online-documentation
community.netwitness.com/...s-site-scripting-xss/ta-p/719453