vendor:
HLstatsX Community Edition
by:
Sora
7,5
CVSS
HIGH
Cross Site Scripting
79
CWE
Product Name: HLstatsX Community Edition
Affected Version From: 1.6.5
Affected Version To: 1.6.5
Patch Exists: NO
Related CWE: N/A
CPE: hlstatsx_ce
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Vista
2010
HLstatsX Community Edition 1.6.5 Cross Site Scripting Vulnerability
HLstatsX Community Edition suffers from a XSS vulnerability. The vulnerability can be exploited by sending a maliciously crafted URL to the vulnerable application. The URL contains a payload which is executed in the browser of the victim.
Mitigation:
Input validation should be used to prevent XSS attacks. The application should validate all user input and reject any malicious input.