PT-2007-4607 · Stphp · Stphp Easynews Pro
Publicado
2007-06-21
·
Atualizado
2017-07-29
·
CVE-2007-3330
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
STphp EasyNews PRO version 4.0
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a news post. The news post is stored in the news/ directory without proper sanitization, enabling the execution of malicious scripts.
Recommendations
For STphp EasyNews PRO version 4.0, ensure that all user input, especially news posts, is properly sanitized before being stored or displayed to prevent the injection of malicious scripts. As a temporary workaround, consider disabling the news posting feature until a proper fix is implemented to sanitize user input.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Stphp Easynews Pro