Havalite CMS v1.0.4 – Multiple Web Vulnerabilities
The vulnerability allows remote attackers to inject own malicious persistent script codes on application-side of the vulnerable module. The vulnerability is located in the `/admin/index.php` file with the vulnerable `$_GET` parameters `file` and `action`. Remote attackers are able to inject own malicious persistent script codes to the vulnerable `$_GET` parameters `file` and `action`. The request method to inject is GET and the attack vector is located on the application-side. The security risk of the persistent input validation vulnerability is estimated as medium with a cvss (common vulnerability scoring system) count of 4.3. Exploitation of the persistent input validation vulnerability requires a low privilege web-application user account and low user interaction. Successful exploitation of the vulnerability results in session hijacking, persistent phishing attacks, persistent external redirects and persistent context manipulation.