Vulnerability Description: Improper Neutralization of Input During Web Page Generation ('Reflected Cross-site Scripting') - CWE-79
Software Version: 6.1
NIST: https://nvd.nist.gov/vuln/detail/CVE-2022-26483
CVSv3: 4.8
Severity: Medium
Credits: Luca Carbone, Antonio Papa, Vincenzo Nigro, Massimiliano Brolli
Cross-site scripting Reflected (XSS) vulnerability affects the Veritas Operations Manager application, which allows authenticated remote attackers to inject arbitrary web script or HTML into HTTP/GET parameter which reflect the user input without sanitization.
The Veritas Operations Manager web application does not properly check parameters sent via GET methods which are included in the server response.