Pachno
cpe:2.3:a:pachno:pachno:*:*:*:*:*:*:*
- <= 1.0.6
A stored cross-site scripting vulnerability has been identified in Pachno version 1.0.6. This issue allows attackers to execute arbitrary HTML and script code by injecting malicious payloads into POST parameters. The vulnerability arises from improper sanitization of input via Request::getRawParameter() and Request::getParameter() calls, enabling injected scripts to be executed in the context of the user's browser session.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.
To reproduce this vulnerability, inject a script or HTML payload into one of the following POST parameters: value, comment_body, article_content, description, or message. This can be done through multiple controllers. The injected payload will be stored in the database and executed in the user's browser session.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.