A cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML via the form parameter post to /public/console/profile/info-submit/.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
http://baigosso.com | broken link url repurposed |
https://github.com/baigoStudio/baigoSSO | third party advisory |
https://github.com/baigoStudio/baigoSSO/ | third party advisory |
https://github.com/baigoStudio/baigoSSO/issues/13 | third party advisory exploit |