CyberRota Analysis
AI-GeneratedOutSystems Service Center is susceptible to a DOM-based Cross-Site Scripting (XSS) vulnerability that allows low-privileged attackers to exploit the system by uploading files with malicious JavaScript filenames. This could lead to unauthorized script execution in the context of the user’s session, potentially compromising sensitive data. Organizations using affected versions of OutSystems Service Center should prioritize patching to version 11.41.2 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
OutSystems Service Center is vulnerable to a DOM-based Cross-Site Scripting (XSS) attack that can be exploited by a low-privileged attacker via the upload of a file with a malicious filename containing JavaScript code. The vulnerability exists in all locations where a file can be attached and prepared for upload to the server. This issue was fixed in OutSystems Service Center version 11.41.2