296,733
Total vulnerabilities in the database
A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (XSS) vulnerability. An attacker able to modify the parameters of any token could use this flaw to trick an authenticated user into executing arbitrary JavaScript code.
| Software | From | Fixed in |
|---|---|---|
| dogtagpki / dogtagpki | 10.0 | 10.8.3.x |
| redhat / certificate_system | 10.0 | 10.0.x |