vendor:
Family Connections
by:
Gjoko 'LiquidWorm' Krstic
7.5
CVSS
HIGH
HTML Injection
79
CWE
Product Name: Family Connections
Affected Version From: 2.3.2002
Affected Version To: 2.3.2002
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP Professional SP3
2011
Family Connections HTML Injection Vulnerability
An attacker can inject arbitrary script code in the browser of an unsuspecting user, allowing them to steal authentication credentials, control site rendering, or launch other attacks.
Mitigation:
Properly sanitize user-supplied input to prevent HTML injection.