Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Reflected Cross Site Scripting (XSS) vulnerability
Vulnerability Description
Cross Site Scripting in UI Request/Response Validation in TIBCO JasperReports Server 8.0.4 and 8.2.0 allows allows for the injection of malicious executable scripts into the code of a trusted application that may lead to stealing the user's active session cookie via sending malicious link, enticing the user to interact.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Vulnerability Type
N/A
Vulnerability Title
TIBCO Software JasperReports Server 安全漏洞
Vulnerability Description
TIBCO Software JasperReports Server是美国TIBCO Software公司的一款可嵌入的报告服务器,它提供可以嵌入到Web或移动设备中的报告和分析功能。 TIBCO Software JasperReports Server 8.0.4版本和8.2.0版本存在安全漏洞,该漏洞源于存在跨站脚本漏洞,允许攻击者将恶意可执行脚本注入到受信任应用程序的代码中。
CVSS Information
N/A
Vulnerability Type
N/A