Online Inventory Manager 3.2 - Persistent Cross-Site Scripting
Vulnerability Description
Online Inventory Manager 3.2 contains a stored cross-site scripting vulnerability in the group description field of the admin edit groups section. Attackers can inject malicious JavaScript through the description field that will execute when the groups page is viewed, allowing potential cookie theft and client-side script execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25265
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Cemal Cihad ÇİFTÇİ
Affected Vendor
Bigprof
View all reports →