PT-2009-1531 · Unknown · World Recipe
Published
2009-02-04
·
Updated
2018-10-11
·
CVE-2008-6056
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
World Recipe version 2.11
Description
The issue allows remote attackers to inject arbitrary web script or HTML, potentially leading to cross-site scripting (XSS) attacks. This can be achieved via the
n parameter to "emailrecipe.aspx", the id parameter to "recipedetail.aspx", and the catid parameter to "validatefieldlength.aspx".Recommendations
For World Recipe version 2.11, consider restricting access to the vulnerable API endpoints "emailrecipe.aspx", "recipedetail.aspx", and "validatefieldength.aspx" until a patch is available. As a temporary workaround, avoid using the parameters
n, id, and catid in the respective affected API endpoints.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
World Recipe