CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ericsson 1Enterprise Content Management Jun 17, 2026 Sep 17, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijacking and full account takeover. |
1Ericsson 1Enterprise Content Management Jun 17, 2026 Sep 17, 2021 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injection. |