On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x...
Moderate severity
Unreviewed
Published
May 6, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 5, 2022
Published to the GitHub Advisory Database
May 6, 2022
Last updated
Feb 1, 2023
On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute template language-specific instructions in the context of the server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
References