PT-2017-13512 · Nexusphp · Nexusphp
Published
2017-09-18
·
Updated
2017-09-21
·
CVE-2017-14534
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NexusPHP version 1.5.beta5.20120707
Description
A Cross Site Scripting (XSS) issue exists, related to the PATH INFO to the "location.php" endpoint, and is connected to the
PHP SELF variable.Recommendations
For NexusPHP version 1.5.beta5.20120707, consider restricting access to the "location.php" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the
PATH INFO to the "location.php" endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexusphp