In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
eclipse business intelligence and reporting tools |