There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/spotweb/spotweb/issues/718 | issue tracking exploit third party advisory |
https://github.com/spotweb/spotweb/commit/2bfa001689aae96009688a193c64478647ba45a1 | third party advisory patch |