Bonita before 2023.2-u2 allows stored XSS via a UI screen in the administration panel.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.bonitasoft.console:bonita-web-server(Maven) | 0 | 10.1.0.W11 | N/A |
| org.bonitasoft.platform:platform-resources(Maven) | 0 | 10.1.0.W11 | N/A |
CVSS Metrics