Loading HuntDB...

GHSA-fr8q-pg27-p54p

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Lack of input sanitization in BMC Control-M branches 9.0.20 and 9.0.21 allows logged-in users for manipulation of generated web pages via injection of HTML code. This might lead to a successful phishing attack for example by tricking users into using a hyperlink pointing to a website controlled by an attacker.

Fix for 9.0.20 branch was released in version 9.0.20.238. Fix for 9.0.21 branch was released in version 9.0.21.200.

Related CVEs

Key Information

GHSA ID
GHSA-fr8q-pg27-p54p
Published
March 18, 2024 12:30 PM
Last Modified
March 18, 2024 12:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 23, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.