CVE-2018-16955

CVE-2018-16955

The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redirect parameter, when prefixed with the https:// scheme, is unsafely reflected in a HTML META tag in the HTTP response.

Source: CVE-2018-16955

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다