[原文]Cross-site scripting (XSS) vulnerability in Groupmax World Wide Web, World Wide Web Desktop, World Wide Web for Scheduler, and Desktop for Scheduler, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
Hitachi Groupmax World Wide Web Multiple Products Unspecified XSS
Remote / Network Access
Loss of Integrity
Groupmax World Wide Web contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate unknown or unspecified variables upon submission to the input form. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.
Currently, there are no known workarounds or upgrades to correct this issue. However, the vendor has released a patch to address this vulnerability.