PT-2018-17789 · Php Scripts Mall · Php Scripts Mall Multi Religion Responsive Matrimonial

Published

2018-02-12

·

Updated

2018-02-26

·

CVE-2018-6864

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHP Scripts Mall Multi religion Responsive Matrimonial version 4.7.2
Description A Cross Site Scripting (XSS) issue exists, allowing for potential code injection via a user profile update parameter.
Recommendations For version 4.7.2, update to a newer version that contains a fix for this issue, or as a temporary workaround, consider restricting access to user profile update functionality to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6864

Affected Products

Php Scripts Mall Multi Religion Responsive Matrimonial