vendor:
Eve-ng
by:
@casp3r0x0 hassan ali al-khafaji
7.5
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Eve-ng
Affected Version From: 5.0.1-13
Affected Version To: 5.0.1-13
Patch Exists: NO
Related CWE:
CPE: a:eve-ng:eve-ng:5.0.1-13
Platforms Tested: Free EVE Community Edition Version 5.0.1-13
2022
Eve-ng 5.0.1-13 – Stored Cross-Site Scripting (XSS)
A stored XSS vulnerability was discovered in the Free EVE Community Edition Version 5.0.1-13 of Eve-ng. An attacker can create a new lab, create a Text label, insert a malicious XSS payload and click save. When any user opens the lab, the XSS will be triggered.
Mitigation:
Input validation should be used to prevent malicious code from being stored in the application.