vendor:
Kryn.cms
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Kryn.cms
Affected Version From: 0.9
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE: a:kryn:cms:0.9
Platforms Tested: Unknown
2011
Cross-Site Scripting Vulnerability in Kryn.cms
Kryn.cms fails to sanitize user-supplied data, allowing an attacker to execute arbitrary script code in the browser of an unsuspecting user. This can lead to the theft of cookie-based authentication credentials and enable other attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate all user-supplied data before displaying it on web pages.