PT-2018-17812 · Php Scripts Mall · Php Scripts Mall Car Rental Script
Publicado
2018-04-12
·
Atualizado
2018-05-16
·
CVE-2018-6904
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP Scripts Mall Car Rental Script version 2.0.8
Description
The issue is related to a Cross-Site Scripting (XSS) problem. It occurs via the
User Name field in an Edit Profile action. This allows for potential malicious script injection.Recommendations
For PHP Scripts Mall Car Rental Script version 2.0.8, consider validating and sanitizing user input in the
User Name field to prevent XSS attacks. As a temporary workaround, restrict the ability to edit profiles until a proper fix is applied.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Php Scripts Mall Car Rental Script