vendor:
iSupport
by:
Or4nG.M4n
8,8
CVSS
HIGH
Html Code injection
79
CWE
Product Name: iSupport
Affected Version From: 1.x
Affected Version To: 1.x
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
iSupport v1.x => Html Code injection to add admin
iSupport v1.x is vulnerable to Html Code injection which allows an attacker to inject malicious HTML code into the vulnerable web application. This can be exploited to add an admin user to the application.
Mitigation:
Input validation should be used to prevent malicious HTML code from being injected into the application.