
Sistema NetAdmin IAM 4 é vulnerável a Cross Site Scripting (XSS), no endpoint /BalloonSave.ashx
The NetAdmin IAM system (version 4.0.30319) presents a Cross Site Scripting (XSS) vulnerability in the /BalloonSave.ashx endpoint, where it is possible to inject a malicious payload in the Content= field. Any authenticated user can exploit this vulnerability by inserting a script in the "Content" field of a request within the described endpoint. This script will be executed whenever the vulnerable page is refreshed.
| CVSS Vector | Description |
|---|---|
| AV | N (Network) |
| AC | L (Low) |
| PR | L (Low) |
| UI | R (Required) |
| S | U (Unchanged) |
| C | H (High) |
| I | H (High) |
| A | N (None) |
https://netadmin.mysystem/BalloonSave.ashxContent=Until the official fix is made available by the vendor, it is recommended to:
For more details on this vulnerability or technical assistance in implementing mitigation measures, contact the vendor's security support.