First published: Fri Dec 21 2018(Updated: )
Cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0 allows remote attackers to inject arbitrary web script or HTML via the query parameter (aka the Search Field).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenzabar Jenzabar | >=8.2.1<=9.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16778 is a cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0.
Yes, Jenzabar v8.2.1 through 9.2.0 is affected by the CVE-2018-16778 vulnerability.
CVE-2018-16778 allows remote attackers to inject arbitrary web script or HTML via the query parameter (aka the Search Field).
CVE-2018-16778 has a severity rating of medium (6.1).
To fix CVE-2018-16778, update your Jenzabar software to a version higher than 9.2.0.