vendor:
Advanced Poll
by:
4.3
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Advanced Poll
Affected Version From: 02.08
Affected Version To: 02.08
Patch Exists: NO
Related CWE:
CPE: a:advanced_poll:advanced_poll:2.08
Platforms Tested:
Cross-Site Scripting in Advanced Poll
The application fails to properly sanitize user-supplied input, allowing an attacker to execute arbitrary script code in the browser of an unsuspecting user. This can lead to the theft of cookie-based authentication credentials and other attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper input validation and output encoding to prevent the execution of arbitrary script code.