Kubysoft Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Kubysoft, a cloud-based ERP software. This vulnerability arises from multiple parameters within the endpoint '/node/kudaby/nodeFN/procedure', allowing the injection of arbitrary client-side scripts. These scripts are immediately reflected in the HTTP response and executed in the victim's browser.
Impact
Exploitation of this vulnerability allows for reflected Cross-Site Scripting, where injected scripts are executed in the context of the user's browser.
Remediation
The Kubysoft team has fixed this vulnerability in the latest version of the software.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
