GroundWork Monitor Enterprise Foundation Admin Interface XSS Vulnerability
9 May. 2013
Summary
GroundWork Monitor Enterprise Foundation Admin Interface /foundation-webapp/admin/manage-performanceDataLabel.jsp suffers from cross site scripting vulnerability
GroundWork Monitor Enterprise contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate input passed via the foundation admin interface to the /foundation-webapp/admin/manage-performanceDataLabel.jsp script. This may allow an attacker to create a specially crafted request that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
Disclosure Timeline:
Disclosure Date :2013-03-08
Vendor Ack Date :2013-02-09
Vendor Solution Date :2013-03-06
Vendor Informed Date :2013-02-06