Question
Cross Site Scripting Issue on Windchill UI
I am using Windchill PDMLink Release 12.0 and Datecode with CPS 12.0.1.0
During Penetration testing, getting Cross Site Scripting (XSS) vulnerability issue on one of the customized UI Pages in Windchill.
Here are the errors that I faced
During Penetration testing, when the Windchill payload is changed via burp suite tool, It is observed that user can add any alert script in the payload and send the request which will cause change in the request and making the system vulnerable to the attackers/hackers
During Penetration testing, getting Cross Site Scripting (XSS) vulnerability issue on one of the customized UI Pages in Windchill.
Here are the errors that I faced
During Penetration testing, when the Windchill payload is changed via burp suite tool, It is observed that user can add any alert script in the payload and send the request which will cause change in the request and making the system vulnerable to the attackers/hackers

