vendor:
Simply Classified 0.2
by:
mr_me
8,8
CVSS
HIGH
Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF)
79,352
CWE
Product Name: Simply Classified 0.2
Affected Version From: 0.2
Affected Version To: 0.2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista
2009
Simply Classified 0.2 XSS & CSRF Vulnerabilities
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability was found in Simply Classified 0.2. An attacker can exploit this vulnerability by crafting a malicious form that contains a hidden input field with a malicious script. When the form is submitted, the malicious script will be executed in the context of the user's browser.
Mitigation:
The vendor should implement proper input validation and sanitization to prevent malicious scripts from being executed.