PHP Scripts Mall Market Place Script 1.0.1 allows XSS via a keyword.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://googlequeens.com/2018/09/04/cve-2018-16455-market-place-script-1-0-1-stored-xss-via-search-by-keyword/ | url repurposed third party advisory exploit |