Description
TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint, allowing attackers to steal session cookies and potentially escalate privileges.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
3.2.41.10.26
Credits
ABABANK REDTEAM
References
www.exploit-db.com/exploits/52086
www.exploit-db.com/exploits/52086 (ExploitDB-52086)
compassplustechnologies.com/ (Compass Technologies Homepage)
www.vulncheck.com/...2411026-stored-cross-site-scripting-xss