An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.
References
Link | Resource |
---|---|
https://www.phpscriptsmall.com/product/investment-mlm/ | Third Party Advisory |
https://securityhitlist.blogspot.com/2019/02/cve-2019-7552-php-scripts-mall.html | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-06-06 09:29
Updated : 2020-04-21 10:52
NVD link : CVE-2019-7552
Mitre link : CVE-2019-7552
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
investment_mlm_software_project
- investment_mlm_software