Описание
Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail parameter).
Ссылки
- Vendor Advisory
- Exploit
- Vendor Advisory
- Exploit
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:agtc_websolutions:php-agtc_membership_system:1.1a:*:*:*:*:*:*:*
EPSS
Процентиль: 63%
0.00439
Низкий
4.9 Medium
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Cross-site scripting (XSS) vulnerability in adduser.php in PHP-AGTC Membership System 1.1a and earlier allows remote attackers to inject arbitrary web script or HTML via the email address (useremail parameter).
EPSS
Процентиль: 63%
0.00439
Низкий
4.9 Medium
CVSS2
Дефекты
NVD-CWE-Other