PT-2018-16176 · Sexstatic · Sexstatic
Bl4De
+1
·
Published
2018-06-01
·
Updated
2023-02-28
·
CVE-2018-3755
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
sexstatic versions 0.6.2 and earlier
sexstatic (all versions)
Description
The issue allows for stored cross-site scripting (XSS) if an attacker can control a filename served by the software. This can lead to HTML injection in directory names, resulting in Stored XSS when a malicious file is embedded with an
iframe element used in the directory name.Recommendations
For sexstatic versions 0.6.2 and earlier, there is no information about a newer version that contains a fix for this issue.
For sexstatic (all versions), do not install or use this module at this time, as there is currently no fix available for this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sexstatic