vendor:
ANE CMS 1
by:
Pratul Agrawal
8,8
CVSS
HIGH
Persistent XSS
79
CWE
Product Name: ANE CMS 1
Affected Version From: ANE CMS 1
Affected Version To: ANE CMS 1
Patch Exists: NO
Related CWE: N/A
CPE: a:ane_cms:ane_cms_1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: php
2020
ANE CMS 1 Persistent XSS Vulnerability
A persistent XSS vulnerability was found in the Admin module of ANE CMS 1. The vulnerability can be exploited by providing malicious script to the ADD LINKS Field which is then stored in the Database. The malicious script is then executed when the user visits the page.
Mitigation:
Input validation should be used to prevent malicious scripts from being stored in the Database.