vendor:
Barcodes Generator Using PHP MySQL and JsBarcode Library
by:
Nikhil Kumar
8.8
CVSS
HIGH
Stored Cross Site Scripting
79
CWE
Product Name: Barcodes Generator Using PHP MySQL and JsBarcode Library
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:egavilanmedia:barcodes_generator_using_php_mysql_and_jsbarcode_library
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu
2020
Barcodes generator 1.0 – ‘name’ Stored Cross Site Scripting
Barcodes generator 1.0 is vulnerable to Stored Cross Site Scripting. An attacker can inject malicious JavaScript code into the 'name' parameter of the 'index.php' page. The malicious code is then stored in the database and executed when the page is loaded.
Mitigation:
Input validation should be used to prevent malicious code from being stored in the database.