vendor:
Lantern CMS
by:
Unknown
5.5
CVSS
MEDIUM
Cross-site scripting (XSS)
79
CWE
Product Name: Lantern CMS
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE:
Platforms Tested:
Unknown
Cross-site scripting vulnerability in Lantern CMS
Lantern CMS fails to sanitize user-supplied input, allowing an attacker to execute arbitrary script code in the browser of an unsuspecting user. This can lead to the theft of authentication credentials and other attacks.
Mitigation:
To mitigate this vulnerability, Lantern CMS should implement proper input sanitization techniques to prevent the execution of script code from user-supplied input.