{ "schema_version": "1.4.0", "id": "GHSA-m5pr-wj64-pvm2", "modified": "2022-05-17T19:57:12Z", "published": "2022-05-17T19:57:12Z", "aliases": [ "CVE-2014-10398" ], "details": "Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client (aka RBS BS-Client. Retail Client) 2.5, 2.4, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) DICTIONARY, (2) FILTERIDENT, (3) FROMSCHEME, (4) FromPoint, or (5) FName_0 parameter and a valid sid parameter value.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-10398" }, { "type": "WEB", "url": "https://www3.trustwave.com/spiderlabs/advisories/TWSL2014-009.txt" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-01-03T20:15:00Z" } }