vendor:
Openserver
by:
Ramikan
6.1
CVSS
MEDIUM
Reflected XSS & HTML Injection
79
CWE
Product Name: Openserver
Affected Version From: 5.0.7
Affected Version To: 6
Patch Exists: YES
Related CWE: CVE-2020-25495
CPE: a:sco:openserver:5.0.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: SCO Openserver 5.0.7 & version 6
2020
SCO Openserver 5.0.7 – ‘section’ Reflected XSS
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.
Mitigation:
Input validation, output encoding, and content security policy can be used to mitigate XSS attacks.