vendor:
Magnolia Content Management Suite
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: Magnolia Content Management Suite
Affected Version From: 2.1
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:magnolia-cms:magnolia
Platforms Tested: Unknown
Unknown
Cross-Site Scripting Vulnerability in Magnolia Content Management Suite
The vulnerability allows an attacker to execute arbitrary script code in the browser of an unsuspecting user by injecting malicious code through user-supplied input. This can lead to the theft of authentication credentials and other attacks.
Mitigation:
Proper input sanitization should be implemented to prevent XSS attacks. Input validation and output encoding can also be used to mitigate the vulnerability.