vendor:
Absolute News Manager .NET
by:
7.5
CVSS
HIGH
Cross-Site Scripting (XSS), SQL Injection, Information Disclosure
79, 89, 200
CWE
Product Name: Absolute News Manager .NET
Affected Version From: 5.1
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:absolute_news_manager:.net:5.1
Platforms Tested:
Absolute News Manager .NET Multiple Remote Vulnerabilities
Multiple vulnerabilities exist in Absolute News Manager .NET, including cross-site scripting (XSS), SQL injection, and information disclosure issues. These vulnerabilities allow attackers to steal authentication credentials, execute arbitrary script code, obtain sensitive information, access or modify data, and exploit underlying database vulnerabilities.
Mitigation:
To mitigate these vulnerabilities, it is recommended to apply the latest patches and updates provided by the vendor. Additionally, input validation and output encoding should be implemented to prevent XSS and SQL injection attacks. Access controls should be enforced to limit sensitive information exposure.