TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the Open Object in Tree endpoint, allowing attackers to steal session cookies and potentially escalate privileges.
| Software | From | Fixed in |
|---|---|---|
| compassplustechnologies / tranzaxis | 3.2.41.10.26 | 3.2.41.10.26.x |