CyberRota Analysis
AI-GeneratedA reflected cross-site scripting (XSS) vulnerability in reportico-web versions up to 8.1.0 allows remote attackers to inject and execute arbitrary JavaScript in users' web browsers through a malicious payload in the reportico_criteria parameter. This could lead to unauthorized actions on behalf of the user, potentially compromising sensitive information. Organizations using affected versions of reportico-web should prioritize patching this vulnerability to protect their users from potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php.