PT-2018-17812 · Php Scripts Mall · Php Scripts Mall Car Rental Script
Published
2018-04-12
·
Updated
2018-05-16
·
CVE-2018-6904
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP Scripts Mall Car Rental Script version 2.0.8
Description
The issue is related to a Cross-Site Scripting (XSS) problem. It occurs via the
User Name field in an Edit Profile action. This allows for potential malicious script injection.Recommendations
For PHP Scripts Mall Car Rental Script version 2.0.8, consider validating and sanitizing user input in the
User Name field to prevent XSS attacks. As a temporary workaround, restrict the ability to edit profiles until a proper fix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Scripts Mall Car Rental Script