mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-01 06:51:35 +02:00
733 B
733 B
CVE-2018-14924
Description
Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nome Completo" (aka user fullname) field.
POC
Reference
- https://medium.com/stolabs/security-issues-on-matera-systems-fba14d207dc9
- https://medium.com/stolabs/security-issues-on-matera-systems-fba14d207dc9