[原文]Cross-site scripting (XSS) vulnerability in form_grupo.html in E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this issue might be resultant from SQL injection.
e-Business Designer admin/form_grupo.html id Parameter XSS
Remote / Network Access
Loss of Integrity
e-Business Designer contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate the 'id' variable upon submission to the admin/form_grupo.html script. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. Additionally, the resulting error message will disclose the software's installation path resulting in a loss of confidentiality. While such information is relatively low risk, it is often useful in carrying out additional, more focused attacks.
Upgrade to version 3.1.4 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.