PT-2019-10132 · Php Scripts Mall · Php Scripts Mall Chartered Accountant : Auditor Website

Published

2019-03-20

·

Updated

2020-08-24

·

CVE-2018-20636

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: PHP Scripts Mall Chartered Accountant : Auditor Website version 2.0.1
Description: The issue concerns HTML injection via the First Name field.
Recommendations: For version 2.0.1, update the software to prevent HTML injection via the First Name field, ensuring proper input validation and sanitization to mitigate the risk.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20636

Affected Products

Php Scripts Mall Chartered Accountant : Auditor Website