In Crea8social 2018.2, there is Reflected Cross-Site Scripting via the term parameter to the /search URI.
References
Link | Resource |
---|---|
https://www.youtube.com/watch?v=QqJFh3Ame9g | Exploit Third Party Advisory |
https://www.seekurity.com/blog/general/multiple-cross-site-scripting-vulnerabilities-in-crea8social-social-network-script/ | Exploit Technical Description Third Party Advisory |
Configurations
Information
Published : 2018-03-28 22:29
Updated : 2018-04-17 17:36
NVD link : CVE-2018-9122
Mitre link : CVE-2018-9122
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
crea8social
- crea8social