Security Issue with HTML Injections within Mustache Templates (MINDBREEZE33995)

ID: MINDBREEZE33995 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 8.2 High 
Status: Final 
CVEs: MINDBREEZE33995 

Summary 

Fixed: Possible stored XSS attacks within unescaped mustache templates 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 24.8 Hotfix 2 Release
  • Mindbreeze InSpire Saas 24.8 Hotfix 2 Release