MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) addNewDept, (2) deptId, or (3) deptDesc parameter to tvserver/server/user/addDepartment.jsp; or the (4) firstName, (5) lastName, or (6) email parameter in a save action to tvserver/user/user.do
Published May 7, 2010
4.3
MEDIUMCVSS 2.0
EPSS 0.85%
Description
Affected products
Remediation
References (1)
Change history (0)
No recorded changes yet.