SVXportal Stored Cross-Site Scripting Vulnerability in User Registration Workflow
Vulnerability
A stored cross-site scripting vulnerability has been identified in SVXportal versions through 2.5. This issue arises in the user registration process, specifically within 'index.php' when it submits data to 'admin/user_action.php'. User-provided information such as first name, last name, and email is saved in the backend database without proper output encoding. This data is later displayed in the administrator interface ('admin/users.php'), enabling an unauthenticated remote attacker to inject arbitrary JavaScript. The injected script executes in the administrator's browser when the affected page is viewed.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the administrator's browser.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
