Zomplog Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Zomplog version 3.9. This issue allows authenticated users to inject malicious scripts while creating new pages. Attackers can exploit this by crafting harmful image source attributes that, when triggered, execute arbitrary JavaScript in the context of the victim's browser.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, log into an account on Zomplog 3.9. Once logged in, add a new page and inject a script by setting the image source (src) attribute to a malicious payload in the onerror attribute. After saving the page, the injected script will execute when the page is loaded.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
