vendor:
phpCMS
by:
Unknown
5.5
CVSS
MEDIUM
Cross-Site Scripting (XSS)
79
CWE
Product Name: phpCMS
Affected Version From: Versions prior to 1.2.1pl1
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:phpcms:phpcms:1.2.1pl1
Platforms Tested:
Unknown
phpCMS Cross-Site Scripting Vulnerability
phpCMS is susceptible to a cross-site scripting vulnerability. This issue occurs when the application fails to properly sanitize user-supplied input before including it in dynamically generated web pages. An attacker can create a malicious URI link with hostile HTML and script code, which, if followed, can render the code in the victim user's web browser. This can lead to theft of cookie-based authentication credentials or other attacks.
Mitigation:
To mitigate this vulnerability, it is recommended to update to phpCMS version 1.2.1pl1 or later. Additionally, enabling both 'STEALTH' and 'STEALTH_SECURE' modes can provide an extra layer of protection.