NEOJAPAN desknet's NEO
cpe:2.3:a:desknets:neo:*:*:*:*:*:*:*
- >= V4.0R1.0, <= V9.0R2.0
A vulnerability exists in desknet's NEO versions 4.0R1.0 to 9.0R2.0, due to a hard-coded cryptographic key. This flaw enables an attacker to create malicious AppSuite applications. The issue affects users logged into desknet's NEO, particularly those who can input or register scripts, as the vulnerability could be exploited to execute arbitrary JavaScript in the user's web browser.
Exploitation of this vulnerability allows for the creation of malicious AppSuite applications, which could potentially be used to execute harmful actions within the AppSuite environment.
Users are advised to update desknet's NEO to version 9.5 R1.0 or later. For those using the PostgreSQL or SQL Server versions, the update module can be downloaded and installed. Customers with a customized version or the Oracle version should contact NEOJAPAN for guidance.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.