Cross Site Scripting vulnerability in DerbyNet v9.0 and below allows attackers to execute arbitrary code via the checkin.php component.
The product uses a denylist-based protection mechanism to defend against XSS attacks, but the denylist is incomplete, allowing XSS variants to succeed.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Derbynet | Derbynet | * | 9.0 (including) |