CE Phoenix Stored Cross-Site Scripting Vulnerability in Currencies Administration Panel
Vulnerability
A stored cross-site scripting vulnerability has been identified in CE Phoenix version 3.0.1, specifically within the currencies administration panel. This vulnerability allows attackers to inject malicious scripts that are executed when administrators view the currencies page. The XSS payloads can be inserted into the title field.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
Reproduction
To reproduce this vulnerability, log into the admin panel and navigate to the currencies administration page. Click to edit an existing currency and enter a script payload into the title field. After saving the changes, return to the currencies page to see the alert generated by the executed script.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
