GOautodial 4.0 - Persistent Cross-Site Scripting
Vulnerability Description
GOautodial 4.0 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through message subjects. Attackers can craft messages with embedded JavaScript that will execute when an administrator reads the message, potentially stealing session cookies or executing client-side attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37018
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Balzabu
References
Affected Vendor
Goautodial
View all reports →