go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

COWELL INFORMATION SYSTEM CO., LTD. enterprise travel management system - Reflected XSS

TVN ID TVN-202209010
CVE ID CVE-2022-39054
CVSS 6.1 (Medium)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected Products Contact tech support from COWELL INFORMATION SYSTEM CO., LTD.
Description Cowell enterprise travel management system has insufficient filtering for special characters within web URL. An unauthenticated remote attacker can inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.
Solution Contact tech support from COWELL INFORMATION SYSTEM CO., LTD.
Credit anxxhzz
Public Date 2022-09-15
Top