vendor:
CMS Papoo Light
by:
Steffen Rösemann
4,3
CVSS
MEDIUM
Persistent XSS
79
CWE
Product Name: CMS Papoo Light
Affected Version From: 6.0.0 Rev. 4701
Affected Version To: 6.0.0 Rev. 4701
Patch Exists: YES
Related CWE: -
CPE: a:papoo:cms_papoo_light:6.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Advisory: Persistent XSS Vulnerability in CMS Papoo Light v6
The CMS Papoo Light Version has a persistent XSS vulnerability in its guestbook functionality and in its user-registration functionality. Papoo Light CMS v6 provides the functionality to post comments on a guestbook via the following url: http://{target-url}/guestbook.php?menuid=6. The input fields with the id „author“ is vulnerable to XSS which gets stored in the database and makes that vulnerability persistent. People can register themselves on Papoo Light v6 CMS at http://{target-url}/account.php?menuid=2. Instead of using a proper username, an attacker can inject HTML and/or JavaScriptcode on the username input-field.
Mitigation:
Update to the latest version