SYNC-2024-020601 - Reflected Cross-Site Scripting (XSS)

Severity: High2024-03-28

Security Advisories

Abstract

Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Reflected Cross-Site Scripting (XSS) for malicious URLs.

Affected Products/Versions

ProductSeverityFixed Release Availability
Oxygen XML Web Author v26.0.0 and olderHigh Oxygen XML Web Author 26.0.0.1 build 2024022608
Oxygen Content Fusion v6.1 and olderHigh Oxygen Content Fusion 6.1 build 2024031214

Mitigation

None

Detail

SYNC-2024-020601

Severity: High

CVSS Score: 8.1

Oxygen XML Web Author v26.0.0 and older and Oxygen Content Fusion v6.1 and older are vulnerable to Reflected Cross-Site Scripting (XSS) by crafting a malicious request that injects unauthorized JavaScript code.

List of Security Advisories