In Crea8social 2018.2, there is Reflected Cross-Site Scripting via the term parameter to the /search URI.
References
Link | Resource |
---|---|
https://www.seekurity.com/blog/general/multiple-cross-site-scripting-vulnerabilities-in-crea8social-social-network-script/ | Exploit Technical Description Third Party Advisory |
https://www.youtube.com/watch?v=QqJFh3Ame9g | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2018-03-29 05:29
Updated : 2024-02-04 19:46
NVD link : CVE-2018-9122
Mitre link : CVE-2018-9122
CVE.ORG link : CVE-2018-9122
JSON object : View
Products Affected
crea8social
- crea8social
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')