vendor:
Library CMS - Powerful Book Management System
by:
Ismail Tasdelen
5.5
CVSS
MEDIUM
Cross-site Scripting
79
CWE
Product Name: Library CMS - Powerful Book Management System
Affected Version From: 2.1.2001
Affected Version To: 2.1.2001
Patch Exists: NO
Related CWE:
CPE: a:kaasoft:library_cms:2.1.1
Platforms Tested:
2018
Library CMS 2.1.1 – Cross-Site Scripting
A Stored XSS vulnerability has been discovered in KAASoft Library CMS - Powerful Book Management System 2.1.1 via the /admin/book/create/ title parameter.
Mitigation:
Encode user input to prevent script injection and implement content security policies.