PY-Livredor index.php HTML Injection...

- AV AC AU C I A
发布: 2003-03-03
修订: 2025-04-13

PY-Livredor does not adequately filter HTML tags from various fields. This may enable an attacker to inject arbitrary HTML code into pages that are generated by the guestbook. The attacker's code may be executed in the web client of users who view the pages generated by the guestbook, in the security context of the website hosting the software. Attackers may potentially exploit this issue to hijack web content or to steal cookie-based authentication credentials.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息