InformationPush Cross-Site Scripting Vulnerability

Vulnerability

A cross-site scripting (XSS) vulnerability exists in InformationPush master version. This issue allows remote attackers to inject malicious scripts or HTML into the webpage, potentially leading to the theft of sensitive information. The vulnerability arises because user-supplied data in the 'title', 'time', and 'msg' parameters is directly embedded into the HTML without any sanitization or validation.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, send a request to 'msg.php' with crafted 'title', 'time', and 'msg' parameters. The injected content will be rendered by the browser, demonstrating the cross-site scripting flaw.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.