Oracle Application Express AnyChart Flash-Based Cross Site Scripting
Posted by deepcore on January 4, 2019 – 6:35 am
Oracle Application Express versions prior to 5.1.4.00.08 suffer from a cross site scripting vulnerability. The vulnerability is located in the OracleAnyChart.swf file. User input passed through the “__externalobjid” GET parameter is not properly sanitized before being passed to the “ExternalInterface.call” method.
Post a reply
You must be logged in to post a comment.