vendor:
EQDKP
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: EQDKP
Affected Version From: 1.3.2c
Affected Version To: Prior versions
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Cross-Site Scripting Vulnerability in EQDKP
The EQDKP application fails to properly sanitize user-supplied input, allowing an attacker to execute arbitrary script code in the browser of an unsuspecting user. This can lead to the theft of cookie-based authentication credentials and the possibility of launching further attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate all user-supplied input before using it in the application.