vendor:
Private Message PHP Script
by:
Borna nematzadeh (L0RD)
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Private Message PHP Script
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: NO
Related CWE: N/A
CPE: 21027192
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
Private Message PHP Script 2.0 – Persistent Cross-Site scripting
Private Message PHP Script 2.0 suffers from persistent cross site scripting. You can put your malicious javascript payload. When target opens your message, payload will be executed before self destruction.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.