vendor:
Zyncro
by:
7.5
CVSS
HIGH
HTML-injection
79
CWE
Product Name: Zyncro
Affected Version From: 3.0.1.20
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
HTML-injection vulnerabilities in Zyncro
Zyncro is prone to multiple HTML-injection vulnerabilities because it fails to sufficiently sanitize user-supplied input. An attacker could exploit these vulnerabilities to execute arbitrary script code in the browser of an unsuspecting victim in the context of the affected website. This may allow the attacker to steal cookie-based authentication credentials or control how the site is rendered to the user. Other attacks are also possible.
Mitigation:
The vendor should sanitize user-supplied input to prevent HTML-injection vulnerabilities. Users should also be cautious when interacting with untrusted websites.