Description
Improper Neutralization of Input During Web Page Generation Cross-site Scripting vulnerability in Jalios JPlatform 10 allows for Reflected XSS and Stored XSS.This issue affects JPlatform 10: before 10.0.8 (SP8), before 10.0.7 (SP7), before 10.0.6 (SP6) and Jalios Workplace 6.2, Jalios Workplace 6.1, Jalios Workplace 6.0, and Jalios Workplace 5.3 to 5.5
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
Any version before 10.0.8
Any version before 10.0.7
Any version before 10.0.6
Credits
Arthur Deloffre (Vozec)
Tristan Bizien (Bizi)
References
community.jalios.com/..._893720/en/security-alert-2025-02-19
issues.jalios.com/browse/JCMS-11259
issues.jalios.com/browse/JCMS-11246
issues.jalios.com/browse/JCMS-11248
vulncheck.com/advisories/jalios-jplatform-xss