vendor:
MemHT Portal
by:
ZonTa
7,5
CVSS
HIGH
Cross Site Scripting
79
CWE
Product Name: MemHT Portal
Affected Version From: 4.0.1
Affected Version To: 4.0.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
MemHT Portal 4.0.1 Persistent Cross Site Scripting Vulnerability [user agent]
MemHT Portal 4.0.1 is vulnerable to a persistent cross-site scripting vulnerability. An attacker can inject malicious JavaScript code into the user agent field of the login page, which will be executed when an administrator views the statistics page. This can be used to steal cookies and hijack user sessions.
Mitigation:
Upgrade to the latest version of MemHT Portal (4.0.2) which includes a fix for this vulnerability.