vendor:
SiteDone
by:
Unknown
7.5
CVSS
HIGH
SQL Injection, Cross-Site Scripting
89
CWE
Product Name: SiteDone
Affected Version From: 2
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Unknown
Unknown
Kempt SiteDone SQL Injection and Cross-Site Scripting Vulnerabilities
The SQL injection vulnerability and cross-site scripting vulnerability in Kempt SiteDone could allow an attacker to steal authentication credentials, control site rendering, compromise the application, access or modify data, or exploit other vulnerabilities in the database.
Mitigation:
Apply security patches and input validation to prevent SQL injection and cross-site scripting attacks. Limit user input and sanitize data before executing queries or displaying content.