Qibo CMS Cross-Site Scripting Vulnerability in Internal Message Module
Vulnerability
A stored cross-site scripting vulnerability has been identified in Qibo CMS version 1.0, specifically within the Internal Message Module. This issue arises from inadequate input validation, allowing attackers to inject malicious JavaScript into private messages. When these messages are viewed by other users, including administrators, the scripts are executed in the context of the user's browser.
Impact
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed when the message is viewed by other users.
Reproduction
To reproduce this vulnerability, send a private message containing a malicious hyperlink that includes JavaScript code, such as one that alerts document cookies. Once the message is sent, it will be stored and executed when the recipient views the message.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
