vendor:
Sockso
by:
Ciaran McNally
7.5
CVSS
HIGH
Persistant XSS
79
CWE
Product Name: Sockso
Affected Version From: <= 1.5
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:sockso:sockso:1.5
Platforms Tested: Windows, Mac, Linux
2012
Sockso
The username input on the registration page is not sanitized, allowing for a persistent XSS vulnerability. An attacker can inject malicious JavaScript code as the username, which is then stored in the database and displayed in the admin panel and user pages. This vulnerability can be exploited remotely. The exploit can also retrieve the admin cookie session.
Mitigation:
The vulnerability has been fixed in the GitHub repository. It is recommended to update to the latest version of Sockso.