vendor:
Virtual Airlines Manager
by:
Peter Blue
5.5
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: Virtual Airlines Manager
Affected Version From: 2.6.2002
Affected Version To: 2.6.2002
Patch Exists: NO
Related CWE:
CPE: a:virtual_airlines_manager:virtual_airlines_manager:2.6.2
Platforms Tested: Linux
2020
Virtual Airlines Manager 2.6.2 – Persistent Cross-Site Scripting
This exploit allows a logged-in user to inject JavaScript code and steal a session ID. Other exploits could also be injected.
Mitigation:
Implement input filtering and validation to prevent the execution of arbitrary code.