vendor:
New STAR
by:
Kagan Çapar
5.5
CVSS
MEDIUM
SQL Injection / Cross-Site Scripting
89
CWE
Product Name: New STAR
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE:
CPE: codecanyon.net/item/new-star-listen-youtube-music/7486113
Platforms Tested: Kali Linux
2018
New STAR 2.1 – SQL Injection / Cross-Site Scripting
ajax.php' working in the input field contains SQL vulnerability. The search section also contains XSS vulnerability.
Mitigation:
Sanitize user input to prevent SQL injection and implement output encoding to prevent XSS attacks.