Products | Versions |
---|---|
TIBCO EBX Add-ons | 5.6.0 and below |
TIBCO EBX Add-ons Cross Site Scripting (XXS) Vulnerability
Original release date: February 22, 2023
Last revised: ---
Source: TIBCO Software Inc.
Description
The component listed above contains an easily exploitable vulnerability that
allows a low privileged attacker with network access to execute stored XSS on
the affected system.
Impact
The impact of this vulnerability includes the theoretical possibility of
unauthorized access to TIBCO EBX® Add-ons data. This includes the ability to
update, insert, or delete data.
CVSS v3.1 Base Score: 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N)