vendor:
SmartFoxServer 2X
by:
LiquidWorm
9.8
CVSS
CRITICAL
Cross-Site Scripting (XSS)
79
CWE
Product Name: SmartFoxServer 2X
Affected Version From: 2.17.0
Affected Version To: 2.17.0
Patch Exists: YES
Related CWE: CVE-2021-25212
CPE: a:gotoandplay:smartfoxserver_2x
Other Scripts:
N/A
Platforms Tested: Windows, Linux/Unix, MacOS, Java, Python
2021
SmartFoxServer 2X 2.17.0 – God Mode Console WebSocket XSS
Authenticated Cross-Site Scripting (XSS) vulnerability in SmartFoxServer 2X 2.17.0 allows remote attackers to inject arbitrary web script or HTML via the AdminTool console. The vulnerability exists due to insufficient sanitization of user-supplied input passed to the AdminTool console. A remote attacker can send a specially crafted request to the vulnerable application and execute arbitrary HTML code in a user's browser session in context of an affected site.
Mitigation:
Upgrade to the latest version of SmartFoxServer 2X.