vendor:
WampServer
by:
Vipin Chaudhary
5.4
CVSS
MEDIUM
Cross Site Scripting
79
CWE
Product Name: WampServer
Affected Version From: 3.1.1
Affected Version To: 3.1.1
Patch Exists: YES
Related CWE: CVE-2018-8732
CPE: a:wampserver:wampserver:3.1.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
WampServer 3.1.1 XSS via CSRF
XSS: cross site scripting via CSRF is remotely exploitable. An attacker can exploit this vulnerability by intercepting the request using a proxy tool and changing the value of the parameter virtual_del[] to '><img src=x onerror=alert(1)>' and forwarding it. This will trigger the XSS vulnerability.
Mitigation:
Update to version 3.1.3