vendor:
EasyService Billing
by:
Özkan Mustafa Akkus (AkkuS)
7.5
CVSS
HIGH
SQL Injection / Cross-Site Scripting
89, 79
CWE
Product Name: EasyService Billing
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: N/A
CPE: a:codecanyon:easyservice_billing
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
EasyService Billing 1.0 – ‘customer-new-s.php’ SQL Injection / Cross-Site Scripting
All of the print and preview pages of EasyService Billing 1.0 have the same vulnerabilities. An attacker can use any of these parameters to inject SQL or XSS payloads.
Mitigation:
Input validation and sanitization should be implemented to prevent SQL injection and XSS attacks.