configuroweb/inventariobasico

configuroweb/inventariobasico

Releases0
Stars17

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM

Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input sanitization on the product name parameter (Nombre:Producto) allowing an authenticated attacker to inject malicious payloads and execute arbitrary JavaScript.