vendor:
HotEditor
by:
Liz0ziM
6.5
CVSS
MEDIUM
Local File Inclusion
22
CWE
Product Name: HotEditor
Affected Version From: HotEditor 4.0
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
eCardMAX HotEditor Local File Inclusion Vulnerability
The eCardMAX HotEditor is prone to a local file inclusion vulnerability. This vulnerability occurs because the application fails to properly sanitize user-supplied input. An unauthorized user can exploit this vulnerability to view files and execute local scripts.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user-supplied input properly. Implementing input validation and using secure coding practices can help prevent local file inclusion vulnerabilities.