vendor:
Amethyst
by:
5.5
CVSS
MEDIUM
HTML-injection
79
CWE
Product Name: Amethyst
Affected Version From: 2000.1.5
Affected Version To: 2000.1.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Hulihan Applications Amethyst HTML-injection vulnerabilities
The application fails to properly sanitize user-supplied input before using it in dynamically generated content. Attacker-supplied HTML and script code can run in the context of the affected browser, potentially allowing the attacker to steal authentication credentials or control the site's rendering.
Mitigation:
Sanitize user-supplied input before using it in dynamically generated content.