vendor:
PHPX
by:
HelloWorld - Ryan Wray
7.5
CVSS
HIGH
Cross-site Scripting, HTML Injection, Account Hijacking
79
CWE
Product Name: PHPX
Affected Version From: PHPX 3.2.3
Affected Version To: Earlier versions
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Multiple vulnerabilities in PHPX
The vulnerabilities allow attackers to perform cross-site scripting attacks, inject HTML code, and hijack user accounts using specially crafted cookies. An attacker can exploit these vulnerabilities by sending malicious requests to the affected PHPX server.
Mitigation:
Upgrade to a patched version of PHPX. Avoid using user-supplied data without proper validation and sanitization. Implement strong authentication mechanisms to prevent account hijacking.