This vulnerability could allow an attacker to store a malicious JavaScript payload in the broadcast message parameter within the admin panel.
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-canopsis-capensis
https://git.canopsis.net/canopsis/canopsis-community/-/blob/develop/community/sources/webcore/src/canopsis-next/src/helpers/html.js?ref_type=heads
https://git.canopsis.net/canopsis/canopsis-community/-/blob/develop/community/sources/webcore/src/canopsis-next/src/config.js?ref_type=heads#L38
Source: Mitre, NVD
Published: 2023-10-03
Updated: 2024-10-01
Base Score: 4.7
Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:N
Severity: Medium
Base Score: 4.8
Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N