zhimengzhe iBarn v1.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the $search parameter at /pay.php.
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special characters such as "<", ">", and "&" that could be interpreted as web-scripting elements when they are sent to a downstream component that processes web pages.
Link | Tags |
---|---|
https://github.com/zhimengzhe/iBarn | product |
https://github.com/zhimengzhe/iBarn/issues/20 | vendor advisory issue tracking exploit |