Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote attackers to execute arbitrary script as other users by injecting script into ext.dll ISAPI.
| Software | From | Fixed in |
|---|---|---|
| working_resources_inc. / badblue | personal_1.7.2 | personal_1.7.2.x |
| working_resources_inc. / badblue | enterprise_1.7.2 | enterprise_1.7.2.x |
| working_resources_inc. / badblue | personal_1.7 | personal_1.7.x |