A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a specially crafted value that will be executed on the victim's browser.
2020-03-18T15:15:11.487
2024-11-21T04:18:30.940
Modified
CVSSv3.1: 4.7 (MEDIUM)
AV:N/AC:H/Au:N/C:N/I:P/A:N
4.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | redhat | enterprise_linux | 7.0 | Yes |
Application | dogtagpki | dogtagpki | ≤ 10.7.3 | Yes |