PT-2019-10132 · Php Scripts Mall · Php Scripts Mall Chartered Accountant : Auditor Website
Published
2019-03-20
·
Updated
2020-08-24
·
CVE-2018-20636
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
PHP Scripts Mall Chartered Accountant : Auditor Website version 2.0.1
Description:
The issue concerns HTML injection via the
First Name field.Recommendations:
For version 2.0.1, update the software to prevent HTML injection via the
First Name field, ensuring proper input validation and sanitization to mitigate the risk.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Scripts Mall Chartered Accountant : Auditor Website