An issue was discovered in PHP Scripts Mall Investment MLM Software 2.0.2. Stored XSS was found in the the My Profile Section. This is due to lack of sanitization in the Edit Name section.
References
Link | Resource |
---|---|
https://securityhitlist.blogspot.com/2019/02/cve-2019-7552-php-scripts-mall.html | Exploit Third Party Advisory |
https://www.phpscriptsmall.com/product/investment-mlm/ | Third Party Advisory |
https://securityhitlist.blogspot.com/2019/02/cve-2019-7552-php-scripts-mall.html | Exploit Third Party Advisory |
https://www.phpscriptsmall.com/product/investment-mlm/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:48
Type | Values Removed | Values Added |
---|---|---|
References | () https://securityhitlist.blogspot.com/2019/02/cve-2019-7552-php-scripts-mall.html - Exploit, Third Party Advisory | |
References | () https://www.phpscriptsmall.com/product/investment-mlm/ - Third Party Advisory |
Information
Published : 2019-06-06 16:29
Updated : 2024-11-21 04:48
NVD link : CVE-2019-7552
Mitre link : CVE-2019-7552
CVE.ORG link : CVE-2019-7552
JSON object : View
Products Affected
investment_mlm_software_project
- investment_mlm_software
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')