Zavy86 WikiDocs
cpe:2.3:a:wikidocs:wikidocs:*:*:*:*:*:*:*
- <= 1.0.78
A reflected cross-site scripting vulnerability has been identified in Zavy86 WikiDocs versions through 1.0.78. The issue arises in the file template.inc.php, where the path argument is not properly sanitized before being outputted. This flaw allows remote attackers to inject malicious scripts that are executed in the context of the user's session.
Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed immediately in the context of the victim's browser session.
The vulnerability can be reproduced by sending a request to the WikiDocs home page with a crafted path argument that includes script tags. The application does not escape the HTML properly, allowing the injected script to run.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.