PT-2019-18965 · Unknown · Online Store

Publicado

2019-10-01

·

Atualizado

2019-10-04

·

CVE-2019-8288

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Online Store version 1.0
Description The issue concerns a Stored XSS in the user view.php file, where the adidas member user variable is not properly sanitized.
Recommendations For Online Store version 1.0, ensure proper sanitization of the adidas member user variable in the user view.php file to prevent Stored XSS attacks.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-8288

Produtos afetados

Online Store