manage (last update Oct 24, 2017) is affected by a Cross Site Scripting (XSS) vulnerability in Application/Home/Controller/GoodsController.class.php. The exit function will terminate the script and print a message which have values from $_POST.
References
Link | Resource |
---|---|
https://github.com/yicenburan/manage/issues/2 | Exploit Issue Tracking Third Party Advisory |
Configurations
Information
Published : 2021-12-01 07:15
Updated : 2021-12-02 07:47
NVD link : CVE-2021-43689
Mitre link : CVE-2021-43689
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
manage_project
- manage