"value":"Tungsten Automation (Kofax) TotalAgility in versions all through\u00a07.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpConnectionId\u00a0parameter manipulation in a form sent to\u00a0endpoints \"/TotalAgility/Kofax/BrowserDevice/ScanFront.aspx\" \nand\u00a0\"/TotalAgility/Kofax/BrowserDevice/ScanFrontDebug.aspx\"\nThis allows for injection of a malicious JavaScript code, leading to a possible information leak.\u00a0\nExploitation is possible only while using POST requests and also requires retrieving/generating a proper VIEWSTATE parameter, which limits the risk of a successful attack."
"value":"Tungsten Automation (Kofax) TotalAgility en todas las versiones hasta la 7.9.0.25.0.954 es vulnerable a ataques XSS reflejado mediante la manipulaci\u00f3n del par\u00e1metro mfpConnectionId en un formato enviado a los endpoints \"/TotalAgility/Kofax/BrowserDevice/ScanFront.aspx\" y \"/TotalAgility/Kofax/BrowserDevice/ScanFrontDebug.aspx\". Esto permite la inyecci\u00f3n de un c\u00f3digo JavaScript malicioso, lo que lleva a una posible fuga de informaci\u00f3n. La explotaci\u00f3n solo es posible mientras se utilizan solicitudes POST y tambi\u00e9n requiere recuperar/generar un par\u00e1metro VIEWSTATE adecuado, lo que limita el riesgo de un ataque exitoso."