CyberRota Analysis
AI-GeneratedA reflected cross-site scripting (XSS) vulnerability in reportico-web versions up to 8.1.0 allows remote attackers to inject and execute arbitrary JavaScript in users' web browsers via a malicious payload in the loadTemplate parameter. This could lead to session hijacking, data theft, or other malicious actions affecting users. Organizations using affected versions of reportico-web should prioritize patching to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php.