vendor:
Express Invoice
by:
Debashis Pal
8.8
CVSS
HIGH
Persistent Cross-Site Scripting (XSS)
79
CWE
Product Name: Express Invoice
Affected Version From: Express Invoice v7.12
Affected Version To: Express Invoice v7.12
Patch Exists: NO
Related CWE: N/A
CPE: a:nch_software:express_invoice
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 SP1(32bit)
2019
Express Invoice 7.12 – ‘Customer’ Persistent Cross-Site Scripting
An authenticated unprivileged user can inject malicious JavaScript code into the 'Customer' field of the Invoices, Items, Customers, and Quotes sections of Express Invoice v7.12. When an authenticated privileged or unprivileged user visits any of these sections, the malicious code will be executed.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in the application.