vendor:
Online News Portal
by:
Richard Jones
9.8
CVSS
HIGH
Stored Cross-Site Scripting
79
CWE
Product Name: Online News Portal
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:sourcecodester:online_news_portal:1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home 19041 (x64_86) + XAMPP 7.2.34
2021
Online News Portal 1.0 – ‘Multiple’ Stored Cross-Site Scripting
Multiple endpoints on the application suffer from Stored XSS injection as a user/supplier and admin. Scripts execute on page load.
Mitigation:
Input validation, output encoding, and content security policy can be used to mitigate XSS attacks.