vendor:
RuubikCMS
by:
expl0i13r
N/A
CVSS
MEDIUM
Stored XSS
79
CWE
Product Name: RuubikCMS
Affected Version From: 1.1.2001
Affected Version To: 1.1.2001
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7
2013
ruubikcms v1.1.1 Stored XSS
RuubikCMS v1.1.1 is vulnerable to Stored XSS. The vulnerability exists in the 'name' parameter of the POST request to '/ruubikcms/ruubikcms/cms/index.php'. Attackers can exploit this vulnerability to execute arbitrary HTML and script code in a user's browser session.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and encode special characters before displaying them on web pages. Regular security updates should also be applied to the RuubikCMS software to patch any known vulnerabilities.