InformationPush Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability exists in InformationPush master version. This issue allows remote attackers to inject malicious scripts or HTML into the webpage, potentially leading to the theft of sensitive information. The vulnerability arises because user-supplied data in the 'title', 'time', and 'msg' parameters is directly embedded into the HTML without any sanitization or validation.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, send a request to 'msg.php' with crafted 'title', 'time', and 'msg' parameters. The injected content will be rendered by the browser, demonstrating the cross-site scripting flaw.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
