PT-2017-18930 · Flatcore · Flatcore

Ghi

·

Published

2017-06-06

·

Updated

2017-06-13

·

CVE-2017-9451

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions flatCore version 1.4.6
Description The issue is related to a cross-site scripting (XSS) vulnerability. It allows remote attackers to inject arbitrary JavaScript code via the PATH INFO in an acp.php URL. This is due to the use of unsanitized $ SERVER['PHP SELF'] to generate URLs.
Recommendations For flatCore version 1.4.6, consider sanitizing the $ SERVER['PHP SELF'] variable to prevent the injection of malicious JavaScript code. As a temporary workaround, restrict access to the acp.php URL to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9451

Affected Products

Flatcore