Cross-site Scripting (XSS) Vulnerabilities

This document provides information about the different cross-site scripting (XSS) vulnerabilities detected in Mobile Device Manager Plus and provides the resolution to secure the server from these vulnerabilities

 

Vulnerability DescriptionDetected byFix available in buildFix released on
XSS vulnerability in the product login screenKen Pyle92698Nov 5, 2019
XSS vulnerability in the Geofencing pageD_ J Dinesh92666Oct 29, 2019
XSS vulnerability in the Audit Log viewD_ J  Dinesh92666Oct 29, 2019
XSS vulnerability in the Upload App pageGuhan Raja92340Aug 17, 2018

Resolution

The fixes for the above mentioned vulnerabilities were released in the respective build numbers. If your MDM server is affected by the vulnerability or is running a version below the build number mentioned, upgrade your Mobile Device Manager Plus server to the appropriate build to resolve the issues.

For more updates on security fixes, follow our Vulnerability Updates forums.