Jenzabar v9.20-v9.2.2 XSS

Published on 10 Jan 2022
Vulnerability

Description

Jenzabar is higher education’s trusted advisor, offering technology solutions and services to institutions both today and in the future.

Jenzabar v9.20-v9.2.2 is vulnerable to cross-site scripting (XSS). An attacker could use the query parameter to inject web script or HTML (/ics?tool=search&query=). Someone must click the link in order to exploit the flaw.

Recommendation

  • Update Jenzabar to the latest version
Anandhu Krishnan
Written by
Lead Engineer

Anandhu is an accomplished Senior Lead Engineer with a strong focus on back-end development. His expertise lies in architecting and optimizing the core of software applications to ensure they run smoothly and efficiently. With a meticulous attention to detail and a deep understanding of data management and server-side operations, Anandhu has been a driving force behind the success of various back-end projects.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo