PT-2018-13581 · Php Scripts Mall · Php Scripts Mall Website Seller Script
Published
2018-10-04
·
Updated
2024-02-14
·
CVE-2018-16456
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP Scripts Mall Website Seller Script version 2.0.5
Description
The issue concerns a cross-site scripting (XSS) problem. XSS is a type of security vulnerability that can allow an attacker to inject malicious scripts into a website, potentially leading to unauthorized access or control. In this case, the XSS vulnerability can be triggered via a keyword.
Recommendations
For version 2.0.5, update to a newer version that includes a fix for this issue, or consider implementing input validation and sanitization for all user-supplied data, especially for keywords, to prevent XSS attacks. As a temporary workaround, consider restricting user input for keywords to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Scripts Mall Website Seller Script