Discovered by Jack Misiura on behalf of The Missing Link Security
Multiple stored cross-site scripting (XSS) vulnerabilities in the OpenAsset Digital Asset Management software allows remote attackers to inject arbitrary JavaScript or HTML to be rendered later by the application via:
Successful exploitation of this issue may allow an attacker to perform unauthorised actions in a user’s security context, when the said user visits the affected pages.
Discovered in: 12.0.19 (Cloud) 11.2.1 (On-Premise)
Fixed in: 12.0.23 (Cloud) 11.4.10 (On-Premise)