vendor:
QuizShock
by:
7.5
CVSS
HIGH
HTML-injection scripting
79
CWE
Product Name: QuizShock
Affected Version From: 1.5.2005
Affected Version To: 1.6.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
QuizShock HTML Injection Scripting Vulnerability
An attacker can inject HTML and script code into the application, allowing them to execute it in the context of the affected site. This can lead to various attacks, such as stealing authentication credentials or controlling how the site is rendered to the user.
Mitigation:
To mitigate this vulnerability, the application should properly sanitize user-supplied input to prevent the injection of malicious code.