Genetechsolutions · Pie Register · CVE-2019-1010207
Name of the Vulnerable Software and Affected Versions:
Genetechsolutions Pie Register version 3.0.15
Description:
The issue allows for Cross Site Scripting (XSS), which can lead to the stealing of session cookies. The vulnerable component is the Login file, specifically the parameters `interim-login`, `wp-lang`, and the supplied URL. An attacker can exploit this by tricking a victim into clicking a malicious link, thereby gaining access to the victim's account.
Recommendations:
For Genetechsolutions Pie Register version 3.0.15, update to version 3.0.16 to resolve the issue.