CVE-2020-14024

Ozeki NG SMS Gateway through 4.17.6 has multiple authenticated stored and/or reflected XSS vulnerabilities via the (1) Receiver or Recipient field in the Mailbox feature, (2) OZFORM_GROUPNAME field in the Group configuration of addresses, (3) listname field in the Defining address lists configuration, or (4) any GET Parameter in the /default URL of the application.
Configurations

Configuration 1

cpe:2.3:a:ozeki:ozeki_ng_sms_gateway:*:*:*:*:*:*:*:*

Information

Published : 2020-09-22 06:15

Updated : 2020-09-26 02:37


NVD link : CVE-2020-14024

Mitre link : CVE-2020-14024

Products Affected
No products.
CWE