vendor:
LiteCMS
by:
7.5
CVSS
HIGH
HTTP response splitting, Cross-site scripting
79, 113
CWE
Product Name: LiteCMS
Affected Version From: 1.5.2002
Affected Version To: 1.5.2002
Patch Exists: NO
Related CWE:
CPE: a:toko:litecms:1.5.2
Platforms Tested:
Toko LiteCMS HTTP Response Splitting and Cross-Site Scripting Vulnerabilities
Toko LiteCMS is prone to an HTTP-response-splitting vulnerability and multiple cross-site scripting vulnerabilities. An attacker can execute arbitrary script code in the browser, steal authentication credentials, and manipulate web content. The vulnerability exists in Toko LiteCMS version 1.5.2.
Mitigation:
Properly sanitize user-supplied input, validate and encode output, and implement security measures to prevent HTTP response splitting attacks.