PT-2020-10389 · Php Scripts Mall · Advanced-Real-Estate-Script
Published
2020-01-05
·
Updated
2020-01-09
·
CVE-2019-20336
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PHP Scripts Mall advanced-real-estate-script version 4.0.9
Description
The issue concerns a problem where the
searchtext parameter in the "search-results.php" endpoint is vulnerable to XSS. This means an attacker could potentially inject malicious scripts into the website, affecting users who visit the page.Recommendations
For version 4.0.9, consider validating and sanitizing the
searchtext parameter in the "search-results.php" endpoint to prevent XSS attacks. As a temporary workaround, restrict access to the search functionality until a proper fix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced-Real-Estate-Script