Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and External Trade Inc. GoldenHorn allows Cross-Site Scripting (XSS). This issue affects GoldenHorn: before 4.25.1121.1.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 4.25.1121.1
Credits
Samet YILMAZ
References
www.usom.gov.tr/bildirim/tr-25-0441
siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0441