A vulnerability classified as problematic has been found in GENI Portal. This affects the function noinvocationiderror of the file portal/www/portal/sliceresource.php. The manipulation of the argument invocationid/invocation_user leads to cross site scripting. It is possible to initiate the attack remotely. The patch is named 39a96fb4b822bd3497442a96135de498d4a81337. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218475.
{
"unresolved_ranges": [
{
"vendor_product": "geni:geni-portal",
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:geni:geni-portal:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "2020-08-27"
}
]
}
]
}