1 results (0.004 seconds)
CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 3
CVE-2022-26088 – BMC Remedy ITSM-Suite 9.1.10 / 20.02 HTML Injection
https://notcve.org/view.php?id=CVE-2022-26088
10 Nov 2022 — An issue was discovered in BMC Remedy before 22.1. Email-based Incident Forwarding allows remote authenticated users to inject HTML (such as an SSRF payload) into the Activity Log by placing it in the To: field. This affects rendering that occurs upon a click in the "number of recipients" field. NOTE: the vendor's position is that "no real impact is demonstrated." Se descubrió un problema en BMC Remedy antes del 22.1. • http://packetstormsecurity.com/files/169863/BMC-Remedy-ITSM-Suite-9.1.10-20.02-HTML-Injection.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •