1) The cross-site scripting vulnerability exist due to improper sanitization of user-supplied input to unspecified components in the CFDIE directory. An authenticated, remote attacker could exploit this vulnerability by convincing a user to follow a malicious link.
Successful exploitation of this vulnerability allows the attacker to include malicious script or HTML code in the users browser in the security context of the affected site.
The information provided herein is on "as is" basis, without warranty of any kind.