vendor:
LNP: Lightweight news Portal
by:
sToRm
7.5
CVSS
HIGH
Cross-Site Scripting, Insecure Administration, Permanent Code Injection, File Upload
CWE
Product Name: LNP: Lightweight news Portal
Affected Version From: v1.0-BETA
Affected Version To: v1.0-BETA
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
LNP: Lightweight news Portal v1.0-BETA Multiple Remote Vulnerabilities
The LNP: Lightweight news Portal v1.0-BETA is vulnerable to multiple remote vulnerabilities including Cross-Site Scripting, Insecure Administration, Permanent Code Injection, and File Upload. These vulnerabilities can be exploited to perform various malicious activities such as executing arbitrary code, injecting malicious scripts, and uploading malicious files.
Mitigation:
The vendor should release a patch to fix these vulnerabilities. In the meantime, users are advised to upgrade to a newer version of the software if available or implement proper input validation and access control measures to mitigate the risk.