vendor:
Ultimate Loan Manager
by:
Metin Yunus Kandemir (kandemir)
6.1
CVSS
MEDIUM
Persistent Cross Site Scripting
79
CWE
Product Name: Ultimate Loan Manager
Affected Version From: V2.0
Affected Version To: V2.0
Patch Exists: YES
Related CWE: CVE-2019-14427
CPE: 2.3:a:web_studio:ultimate_loan_manager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Webapps
2019
Web Studio Ultimate Loan Manager V2.0 – Persistent Cross Site Scripting
XSS exists in WEB STUDIO Ultimate Loan Manager 2.0 by adding a branch under the Branches button that sets the notes parameter with crafted JavaScript code.
Mitigation:
Input validation and output encoding should be used to prevent XSS attacks.