PT-2026-71960 · Outsystems · Lifetime+1
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OutSystems Service Center versions prior to 11.41.2
OutSystems Lifetime versions prior to 11.28.2.3955
Description
OutSystems Service Center is subject to a DOM-based Cross-Site Scripting (XSS) issue, where a low-privileged attacker can execute JavaScript code by uploading a file with a malicious filename. This occurs in any location where files are attached for server upload.
OutSystems Lifetime contains an authorization bypass flaw involving the
ApplicationID parameter. This allows any authenticated user to access the Change Log, exposing application names and actions performed by other users.Recommendations
Update OutSystems Service Center to version 11.41.2.
Update OutSystems Lifetime to version 11.28.2.3955.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lifetime
Hp Service Center