RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user with access to modify link name fields could potentially exploit this vulnerability to execute code in a victim's browser.
2021-05-26T04:15:09.093
2024-11-21T06:00:53.360
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rsa | archer | < 6.6.0.8 | Yes |
Application | rsa | archer | < 6.7.0.8 | Yes |
Application | rsa | archer | < 6.8.0.5 | Yes |
Application | rsa | archer | < 6.9.1.1 | Yes |