wangl1989 mysiteforme
cpe:2.3:a:wangl1989:mysiteforme:*:*:*:*:*:*:*
- 1.0
A cross-site scripting (XSS) vulnerability has been identified in Wangl1989 MySiteForMe version 1.0. The issue arises in the RestResponse function of the SiteController file, where incoming data is not properly sanitized, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
To reproduce this vulnerability, navigate to the blog editing interface of the application. The 'edit' method in the SiteController will not filter user input, allowing for the insertion of a script tag containing JavaScript, such as an alert. Once the input is saved, the injected script will execute when the blog is viewed.
Users are advised to update to the latest version of MySiteForMe, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.