PT-2022-27064 · Unknown · Backclick Professional

Published

2022-11-16

·

Updated

2022-11-18

·

CVE-2022-44002

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions BACKCLICK Professional version 5.9.63
Description An issue was discovered due to insufficient output encoding of user-supplied data, making the web application vulnerable to cross-site scripting (XSS) at various locations.
Recommendations For BACKCLICK Professional version 5.9.63, consider implementing proper output encoding for user-supplied data to prevent cross-site scripting (XSS) attacks. As a temporary workaround, restrict access to sensitive areas of the web application until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-44002

Affected Products

Backclick Professional