vendor:
MercuryBoard
by:
Unknown
7.5
CVSS
HIGH
Cross-Site Scripting (XSS)
79
CWE
Product Name: MercuryBoard
Affected Version From: 1.1.2005
Affected Version To: Unknown (other versions may also be affected)
Patch Exists: NO
Related CWE: Unknown
CPE: a:mercuryboard:mercuryboard:1.1.5
Platforms Tested: Unknown
Unknown
MercuryBoard Cross-Site Scripting Vulnerability
The MercuryBoard application is prone to a cross-site scripting vulnerability due to improper input sanitization. An attacker can exploit this vulnerability to execute arbitrary script code in the browser of a user visiting the affected site, potentially leading to the theft of authentication credentials and other attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to implement proper input validation and sanitization techniques to prevent the execution of malicious scripts.