vendor:
NuKed-Klan
by:
Unknown
7.5
CVSS
HIGH
HTML Injection
79
CWE
Product Name: NuKed-Klan
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: a:nukedklan:nukedklan
Platforms Tested:
Unknown
HTML Injection in NuKed-Klan ‘submit URI link’ function
The 'submit URI link' function in NuKed-Klan is prone to a HTML injection vulnerability. This is due to a lack of input validation on the 'website name' input field of the form. Attackers can exploit this vulnerability to manipulate web content or steal cookie-based authentication credentials. They can also perform arbitrary actions as the victim user.
Mitigation:
Implement proper input validation and sanitization to prevent HTML injection attacks. Also, ensure that cookie-based authentication credentials are properly protected.