vendor:
Clansphere CMS
by:
Sinem Sahin
8.8
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Clansphere CMS
Affected Version From: 2011.4
Affected Version To: 2011.4
Patch Exists: NO
Related CWE:
CPE: a:clansphere:clansphere:2011.4
Platforms Tested: Windows & XAMPP
2022
Clansphere CMS 2011.4 – Stored Cross-Site Scripting (XSS)
Clansphere CMS 2011.4 is vulnerable to stored cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability by creating a malicious payload and entering it into the username field of the buddy list creation page. When a user visits the page, the malicious payload will be executed.
Mitigation:
To mitigate this vulnerability, users should ensure that all input is properly sanitized and validated before being used in the application.