vendor:
Zuz Music
by:
Deyaa Muhammad
3.5
CVSS
MEDIUM
Persistent Cross-site Scripting
79
CWE
Product Name: Zuz Music
Affected Version From: 2.1
Affected Version To: 2.1
Patch Exists: NO
Related CWE: N/A
CPE: a:zuz_host:zuz_music
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WIN7_x68/Linux
2019
Zuz Music 2.1 – ‘zuzconsole/___contact ‘ Persistent Cross-site Scripting
ZuzMusic 2.1 suffers from a persistent Cross-Site Scripting vulnerability. An attacker can inject malicious JavaScript code into the vulnerable parameters name, subject and message. The injected JavaScript code will be executed when the Administrator open the malicious message.
Mitigation:
Input validation should be done on the server-side to prevent malicious code injection.