Loading product vulnerabilities…
Total
2
Critical
0
High
0
Medium
2
CISA KEV
0
A cross-site scripting (XSS) vulnerability in ICT Protege GX/WX v2.08 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter.
An access control issue in ICT Protege GX/WX 2.08 allows attackers to leak SHA1 password hashes of other users.