Quiter Gateway Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in Quiter Gateway versions prior to 4.7.0. This vulnerability allows an attacker to execute JavaScript in the victim's browser by sending a malicious URL through the id_concesion parameter in the /<Client>FacturaE/VerFacturaPDF endpoint.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can execute JavaScript in the context of the victim's browser.
Remediation
Users can upgrade to Quiter Gateway version 4.7.0 or later to address this vulnerability. Quiter has applied the fix to all affected customers.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
