vendor:
Plesk Reloaded
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Plesk Reloaded
Affected Version From: Plesk Reloaded 7.1 (demo version)
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:plesk:plesk_reloaded:7.1
Platforms Tested:
Unknown
Cross-Site Scripting Vulnerability in Plesk Reloaded
The application fails to properly sanitize user-supplied URI input, allowing a remote attacker to create a malicious URI link containing hostile HTML and script code. When followed, this link can render the hostile code in the victim user's web browser, potentially leading to theft of authentication credentials or other attacks.
Mitigation:
Proper input validation and sanitization should be implemented to prevent the execution of malicious code.