vendor:
User Management
by:
Ismail Tasdelen
5.4
CVSS
MEDIUM
Cross-site Scripting
79
CWE
Product Name: User Management
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: YES
Related CWE: CVE-2018-18419
CPE: 2.3:a:ardawan:user_management:1.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
User Management 1.1 – Cross-Site Scripting
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filename to the /account URI.
Mitigation:
Input validation should be used to prevent malicious input from entering the system.