vendor:
Monstra
by:
tmrswrr
4.3
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Monstra
Affected Version From: 3.0.4
Affected Version To: 3.0.4
Patch Exists: NO
Related CWE:
CPE: a:monstra_cms_project:monstra:3.0.4
Platforms Tested:
2023
Monstra 3.0.4 – Stored Cross-Site Scripting (XSS)
This exploit allows an attacker to inject malicious scripts into the Monstra CMS admin panel. By editing a page and inserting a payload in the Name field, an attacker can execute arbitrary JavaScript code on the affected website.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and validate input fields to prevent the execution of malicious scripts.