Diskover Web Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Diskover Web version 2.3.0 Community Edition. The issue arises from unsanitized GET parameters, including maxage, maxindex, index, path, q (query), and doctype, which are directly echoed into the HTML response. This flaw allows attackers to inject and execute arbitrary JavaScript when a victim visits a maliciously crafted URL.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, send a GET request to 'selectindices.php' or 'search.php' with one of the vulnerable parameters (maxage, maxindex, index, q, or doctype) included. The unsanitized input will be reflected in the response, executing any injected JavaScript. This vulnerability can also be demonstrated by including the malicious script in the 'path' parameter when accessing 'd3_data_bar_mtime_searchresults.php' or 'd3_data_search.php'.

Added: Aug 27, 2025, 3:25 PM
Updated: Aug 27, 2025, 4:25 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
7.7
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.