PHP Scripts Mall Website Seller Script 2.0.5 has XSS via a keyword. NOTE: This may overlap with CVE-2018-6870 which has XSS via the Listings Search feature.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://googlequeens.com/2018/09/04/cve-2018-16456-website-seller-scriptwebsite-seller-script-2-0-5-stored-xss-via-search-by-keyword/ | url repurposed exploit third party advisory |