vendor:
Wchat
by:
Borna nematzadeh (L0RD)
7.5
CVSS
HIGH
Persistent cross site scripting
79
CWE
Product Name: Wchat
Affected Version From: 1.5
Affected Version To: 1.5
Patch Exists: NO
Related CWE: N/A
CPE: a:codecanyon:wchat
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
Wchat – Fully Responsive PHP AJAX Chat Script 1.5 – Persistent cross site scripting
Wchat is vulnerable to persistent cross site scripting. An attacker can inject malicious JavaScript code into the textarea of the 'Edit profile' page. The malicious code will be executed when someone visits the profile page.
Mitigation:
Input validation should be used to prevent malicious code from being injected.