PT-2018-17786 · Php Scripts Mall · Php Scripts Mall Lawyer Search Script
Published
2018-02-12
·
Updated
2020-03-11
·
CVE-2018-6861
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP Scripts Mall Lawyer Search Script version 1.0.2
Description
A Cross Site Scripting (XSS) issue exists, allowing for potential code injection via a profile update parameter.
Recommendations
For PHP Scripts Mall Lawyer Search Script version 1.0.2, avoid using the profile update feature until a fix is available. As a temporary workaround, consider restricting access to the profile update functionality to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Scripts Mall Lawyer Search Script