Campcodes Division Regional Athletic Meet Game Result Matrix System Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System version 2.1. The issue resides in the save-games.php file, where the game_name parameter is not properly sanitized, allowing remote attackers to inject malicious scripts. These scripts could be executed in the context of the user's browser, potentially compromising their security and privacy.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
Reproduction
To reproduce this vulnerability, navigate to the save-games.php page and enter a payload, such as a script link, into the 'game_name' box. After submitting the form, the injected script will execute when the page is refreshed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
