vendor:
XAMPP
by:
Rafael Pedrero
6.1
CVSS
MEDIUM
Cross Site Scripting
79
CWE
Product Name: XAMPP
Affected Version From: XAMPP 1.8.2
Affected Version To: XAMPP 5.6.8
Patch Exists: NO
Related CWE: CVE-2019-8924
CPE: a:apache:xampp
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: All
2019
Cross Site Scripting in XAMPP 5.6.8 (and previous)
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued. Affected Product Code Base XAMPP 1.8.2 (and previous).
Mitigation:
Update to last version.