vendor:
OneCMS
by:
Unknown
7.5
CVSS
HIGH
SQL-Injection, Cross-Site Scripting
Unknown
CWE
Product Name: OneCMS
Affected Version From: 2.6.2001
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
Multiple SQL-Injection and Cross-Site Scripting Vulnerabilities in OneCMS
The OneCMS application is prone to multiple SQL-injection and cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. Exploiting these vulnerabilities could allow an attacker to steal authentication credentials, control the site's rendering, compromise the application, access or modify data, or exploit other latent vulnerabilities in the database.
Mitigation:
To mitigate these vulnerabilities, it is recommended to sanitize all user-supplied input and implement proper input validation and output encoding. Regular security audits and updates to the latest version of OneCMS can also help prevent these vulnerabilities.