PT-2017-14995 · Unknown · Paid To Read Script
Published
2017-12-20
·
Updated
2018-01-03
·
CVE-2017-17778
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Paid To Read Script version 2.0.5
Description
The issue concerns a security problem where an attacker can execute malicious scripts. This is possible through the
tier parameter in the "referrals.php" endpoint or the uid parameter in the "admin/userview.php" endpoint.Recommendations
For Paid To Read Script version 2.0.5, consider restricting access to the
referrals.php and admin/userview.php endpoints until a fix is available. As a temporary workaround, avoid using the tier and uid parameters in these endpoints to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Paid To Read Script