vendor:
PragmaMX
by:
http://hauntit.blogspot.com
8,8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: PragmaMX
Affected Version From: 1.12.0
Affected Version To: 1.12.0
Patch Exists: YES
Related CWE: N/A
CPE: a:pragmamx:pragmamx:1.12.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: LAMP
2012
Persistent XSS in PragmaMX 1.12.0 for logged in users
Vulnerability exists in 'Private Messages'. It depends on what code is added to the $message parameter. Persistent XSS code could be added when replying to a message. The bug is in the 'modules.php' file in the 'Private_Messages' module.
Mitigation:
Upgrade to the latest version of PragmaMX