vendor:
CMS WebManager-Pro
by:
Unknown
7.5
CVSS
HIGH
SQL Injection and Cross-Site Scripting
89, 79
CWE
Product Name: CMS WebManager-Pro
Affected Version From: 7.4.2003
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Unknown
CMS WebManager-Pro SQL Injection and Cross-Site Scripting Vulnerabilities
The SQL injection vulnerability and the cross-site scripting vulnerability in CMS WebManager-Pro could allow an attacker to steal authentication credentials, compromise the application, access or modify data, or exploit other vulnerabilities in the database.
Mitigation:
Apply patches or updates provided by the vendor to fix the vulnerabilities. Ensure input validation and output encoding are implemented to prevent SQL injection and cross-site scripting attacks.