CVE-2018-14875

An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:polarisft:intellect_core_banking:9.7.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-04-30 19:29

Updated : 2024-02-04 20:20


NVD link : CVE-2018-14875

Mitre link : CVE-2018-14875

CVE.ORG link : CVE-2018-14875


JSON object : View

Products Affected

polarisft

  • intellect_core_banking
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')