PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has Stored XSS in the Profile Update page via the My Name field.
References
| Link | Resource |
|---|---|
| https://securityhitlist.blogspot.com/2019/02/cve-2019-7553-stores-xss-in-php-scripts.html | Exploit Third Party Advisory |
| http://74.124.215.220/~projclient/client/auditor/profile.php | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-06-06 16:29
Updated : 2019-06-09 19:50
NVD link : CVE-2019-7553
Mitre link : CVE-2019-7553
JSON object : View
Products Affected
chartered_accountant_\
- _auditor_website_project
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
