vendor:
Deskpro
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting
79
CWE
Product Name: Deskpro
Affected Version From: 1.1.2000
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:deskpro:deskpro:1.1.0
Platforms Tested: Unknown
Unknown
Cross-Site Scripting Vulnerability in Deskpro
The Deskpro application fails to properly sanitize user-supplied input, allowing an attacker to execute arbitrary script code in the browser of an unsuspecting user. This can lead to the theft of cookie-based authentication credentials and other attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user-supplied input before using it in the application.