vendor:
phpMoneyBooks
by:
chap0
7,5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: phpMoneyBooks
Affected Version From: 1.03
Affected Version To: 1.03
Patch Exists: YES
Related CWE: N/A
CPE: phpmoneybooks
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012
phpmoneybooks 1.03 Stored XSS
phpmoneybooks 1.03 is vulnerable to Stored XSS vulnerability enabling an attacker to execute arbitrary JavaScript code withing the application. The vulnerability can be utilized when adding a new bank account or customer account. Users other then the admin account are able to input this information which in return can enable the super admin user to fall victim to this attack. The vulnerable index pages reside in /banks/index.php and /customers/index.php.
Mitigation:
Upgrade to 1.04