In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient sanitization of the _GET['replace'] variable. As a result, arbitrary Javascript code can get executed.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/icecoder/ICEcoder | third party advisory product |
https://groups.google.com/g/icecoder/c/xcAc8_1UPxQ | third party advisory exploit |
https://prophaze.com/cve/icecoder-8-0-multipe-results-php-replace-cross-site-scripting/ | third party advisory |