Critical
CVSS 9.8
Overview
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by defa...
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.
This vulnerability is rated 🔴 CRITICAL.
Recommended actions: