rochesecurity/Roche-CVEs

rochesecurity/Roche-CVEs

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

In HT2 Labs Learning Locker 3.15.1, it's possible to inject malicious HTML and JavaScript code into the DOM of the website via the PATH_INFO to the dashboards/ URI.

6.1 MEDIUM4.3 MEDIUM

In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login.