Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters.
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
Updated vendor and product information, marked severity as HIGH, and noted that the vulnerability is actively exploited.
Initial creation