vendor:
Auto CMS
by:
Unknown
5.5
CVSS
MEDIUM
Cross-site scripting (XSS)
79
CWE
Product Name: Auto CMS
Affected Version From: 1.6
Affected Version To: 1.6
Patch Exists: NO
Related CWE:
CPE: a:roberto_aleman:auto_cms:1.6
Platforms Tested:
Unknown
Cross-site scripting vulnerability in Auto CMS
The Auto CMS application is prone to a cross-site scripting vulnerability due to insufficient sanitization of user-supplied input. An attacker can exploit this vulnerability to execute arbitrary script code in the browser of an unsuspecting user, potentially stealing authentication credentials and launching further attacks.
Mitigation:
It is recommended to update to the latest version of Auto CMS or apply a patch provided by the vendor. Additionally, input validation and sanitization should be implemented to prevent XSS attacks.