vendor:
ChemInv
by:
Bobby Cooke
N/A
CVSS
N/A
Persistent Cross-Site Scripting
CWE
Product Name: ChemInv
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: CentOS
2020
ChemInv 1.0 – Authenticated Persistent Cross-Site Scripting
ChemInv suffers from a persistent cross-site scripting vulnerability(XSS). This vulnerability can be exploited to have all users of the system, with read access to the project, execute malicious client-side code; every time the users views the 'Projects' or 'Add Chemicals' tab. The application's source code mitigates SQL injection (SQLi), but fails to sanitize HTML and JavaScript injections to the SQL database.