vendor:
Click2Magic
by:
Shivam Verma(cyb3r_n3rd)
8.8
CVSS
HIGH
Stored Cross-Site Scripting
79
CWE
Product Name: Click2Magic
Affected Version From: 1.1.5
Affected Version To: 1.1.5
Patch Exists: NO
Related CWE: N/A
CPE: 2.3:a:click2magic:click2magic:1.1.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2020
Click2Magic 1.1.5 – Stored Cross-Site Scripting
This Vulnerability Leads an Attacker to Inject Malicious Payloads in Chat section each time admin/user visits and manages the user data, The Malicious Payload(XSS) triggers and attacker can capture the admin cookies and access the users Data
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.