ssCMS v.2.1.0 Cross-Site Scripting Security Vulnerability
Description
Input passed to the "keywords" parameter in the search functionality is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Confirmed in version v.2.1.0. Other versions may also be affected.
Impact
This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
References
Secunia SA19399
Product Homepage
|
|