PT-2026-30484 · Php Scripts Mall · Ask Expert Script
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ask Expert Script version 3.0.5
Description
Unauthenticated attackers can inject malicious code by manipulating URL parameters. The issue involves cross-site scripting (XSS), where script tags can be injected via the
cateid parameter in the 'categorysearch.php' endpoint, and SQL injection, where SQL code can be injected via the view parameter in the 'list-details.php' endpoint to execute arbitrary code or extract database information.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
cateid parameter in the 'categorysearch.php' endpoint.
Avoid using the view parameter in the 'list-details.php' endpoint.Exploit
SQL injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ask Expert Script