PT-2007-4607 · Stphp · Stphp Easynews Pro

Published

2007-06-21

·

Updated

2017-07-29

·

CVE-2007-3330

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions STphp EasyNews PRO version 4.0
Description A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via a news post. The news post is stored in the news/ directory without proper sanitization, enabling the execution of malicious scripts.
Recommendations For STphp EasyNews PRO version 4.0, ensure that all user input, especially news posts, is properly sanitized before being stored or displayed to prevent the injection of malicious scripts. As a temporary workaround, consider disabling the news posting feature until a proper fix is implemented to sanitize user input.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3330

Affected Products

Stphp Easynews Pro