vendor:
EasyCreate
by:
ManhNho
5.4
CVSS
MEDIUM
Stored Cross-Site Scripting
79
CWE
Product Name: EasyCreate
Affected Version From: 3.2.1
Affected Version To: 3.2.1
Patch Exists: YES
Related CWE: CVE-2018-9236, CVE-2018-9237
CPE: a:iscripts:easycreate:3.2.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
iScripts Easycreate 3.2.1 – Stored Cross-Site Scripting
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the 'Site Description' and 'Site Title' fields. An attacker can inject malicious JavaScript code into the 'Site Description' and 'Site Title' fields, which will be executed in the browser of the victim when the page is loaded.
Mitigation:
Input validation should be used to prevent the injection of malicious code into the 'Site Description' and 'Site Title' fields.