PT-2014-8500 · Webasyst · Webasyst Shop-Script
Published
2014-10-21
·
Updated
2017-09-08
·
CVE-2014-8377
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Webasyst Shop-Script version 5.2.2.30933
Description
A cross-site scripting (XSS) issue allows remote attackers to inject arbitrary web script or HTML via the phone number field in a new contact to "phpecom/index.php/webasyst/contacts/".
Recommendations
For Webasyst Shop-Script version 5.2.2.30933, avoid using the phone number field in the new contact form until a fix is available. As a temporary workaround, consider validating and sanitizing user input for the phone number field to prevent malicious script injection.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webasyst Shop-Script