vendor:
Sage Extension Feed
by:
Unknown
5.5
CVSS
MEDIUM
HTML-injection
79
CWE
Product Name: Sage Extension Feed
Affected Version From: 1.3.2009
Affected Version To: 1.3.2009
Patch Exists: NO
Related CWE:
CPE: a:sage_extension_feed:1.3.9
Platforms Tested:
2007
Sage Extension Feed HTML-injection vulnerability
The Sage Extension Feed application fails to properly sanitize user-supplied input before using it in dynamically generated content, leading to an HTML-injection vulnerability. Hostile HTML and script code can be injected into vulnerable sections of the application, which can be rendered in the browser of a user viewing a malicious RSS feed.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user-supplied input before using it in dynamically generated content. Additionally, users should be cautious when viewing RSS feeds from untrusted sources.