Mango Automation 2.6.0 Cross Site Scripting

Discussion in 'News Aggregator' started by Packet Storm, 29 Sep 2015.

  1. Packet Storm

    Packet Storm Guest

    Mango Automation version 2.6.0 is prone to a reflected cross site scripting vulnerability due to a failure to properly sanitize user-supplied input to the 'username' POST parameter in the 'login.htm' script. Attackers can exploit this issue to execute arbitrary HTML and script code in a user's browser session.

    Continue reading...
     

Share This Page

Loading...