vendor:
inoERP
by:
strider
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: inoERP
Affected Version From: 2000.7.2
Affected Version To: 2000.7.2
Patch Exists: No
Related CWE:
CPE: a:inoideas:inoerp:0.7.2
Platforms Tested: Debian 10 Buster x64 / Kali Linux
2019
InoERP 0.7.2 – Persistent Cross-Site Scripting
There is a security flaw on the comment section, which allows to make persistent XSS without any authentication. An attacker could use this flaw to gain cookies to get into an account of registered users.
Mitigation:
Implement input validation and output encoding to prevent XSS attacks. Also, enforce authentication for comment submissions.