PT-2022-20677 · Haraj · Haraj
Abdulaziz Saad
+1
·
Published
2022-06-16
·
Updated
2022-06-27
·
CVE-2022-31301
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Haraj version 3.7
Description
A stored cross-site scripting (XSS) issue was found in the Post Ads component. This allows an attacker to inject malicious scripts into the application, potentially leading to unauthorized actions or data theft.
Recommendations
For Haraj version 3.7, update the Post Ads component to remove the stored XSS vulnerability. As a temporary workaround, consider restricting access to the Post Ads feature until a patch is available. Avoid using the Post Ads component with untrusted input until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Haraj