vendor:
LANGO - Codeigniter Multilingual Script
by:
Ismail Tasdelen
4.8
CVSS
MEDIUM
Code Injection
79
CWE
Product Name: LANGO - Codeigniter Multilingual Script
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: CVE-2018-18416
CPE: a:pokkho:lango_codeigniter_multilingual_script
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
LANGO Codeigniter Multilingual Script 1.0 – Cross-Site Scripting
LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name parameter to the admin/settings/update URI.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.