vendor:
Express Accounts Accounting
by:
Debashis Pal
3.1
CVSS
MEDIUM
Persistent Cross-Site Scripting (XSS)
79
CWE
Product Name: Express Accounts Accounting
Affected Version From: Express Accounts Accounting v7.02
Affected Version To: Express Accounts Accounting v7.02
Patch Exists: NO
Related CWE: N/A
CPE: a:nch_software:express_accounts_accounting
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 SP1(32bit)
2019
Express Accounts Accounting 7.02 – Persistent Cross-Site Scripting
Express Accounts Accounting v7.02 is vulnerable to Persistent Cross-Site Scripting (XSS). An authenticated unprivileged user can inject malicious payloads into the Customer field of Invoices, Sales Orders, Items, Customers, and Quotes sections. When an authenticated privileged or unprivileged user visits any of these sections, the payload will be executed.
Mitigation:
Input validation should be used to prevent malicious payloads from being injected into the Customer field.