phpshe
cpe:2.3:a:phpshe:phpshe:*:*:*:*:*:*:*
- v1.8
A reflected cross-site scripting vulnerability has been identified in phpshe version 1.8. The issue arises in the file api.php, specifically within the cron module, where the act parameter is not properly sanitized before being output to the HTML page. This vulnerability allows attackers to execute malicious scripts in the context of the user's browser, potentially stealing cookies or other sensitive information.
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.