SVX Portal Cross-Site Scripting Vulnerability Allowing Arbitrary Code Execution
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in SVX Portal version 2.7A. The issue arises in the 'last_heard_page.php' component, where the 'TG' parameter is vulnerable to reflected XSS attacks. This flaw allows the execution of arbitrary JavaScript in the context of the victim's browser.
Impact
Exploitation of this vulnerability could lead to cross-site scripting, allowing for the execution of malicious scripts in the context of the user's session.
Reproduction
To reproduce this vulnerability, send a request to 'last_heard_page.php' with a crafted 'TG' parameter that includes an image tag (with an invalid image source) using an 'onerror' event. This will trigger the XSS by executing JavaScript in the victim's browser.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
