CVE-2018-7057
Published Feb 15, 2018RoomWizard before 4.4.x allows XSS via the HelpAction.action pageName parameter.
Vendor/product archive
3 CVEs tagged to steelcase / roomwizard — 0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.
RoomWizard before 4.4.x allows XSS via the HelpAction.action pageName parameter.
RoomWizard before 4.4.x allows remote attackers to obtain potentially sensitive information about IP addresses via /getGroupTimeLineJSON.action.
GroupViewProxyServlet in RoomWizard before 4.4.x allows SSRF via the url parameter.