StarSea99 Starsea-Mall Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in StarSea99's Starsea-Mall version 1.0. The issue arises in the admin goods update interface, where the goodsName parameter is not properly sanitized. This lack of input validation allows attackers to inject malicious JavaScript, potentially leading to the execution of harmful scripts in the user's browser. The vulnerability can be exploited remotely.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, send a request to the /admin/goods/update endpoint with an unsanitized goodsName parameter. Include a payload that consists of JavaScript, such as an image tag with an onerror event. The injected script will be executed, demonstrating the cross-site scripting vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
