Cross-Site Scripting Vulnerability in Proman Xpress by Proman
CVE-2012-4266

Currently unrated

Key Information:

Vendor
CVE Published:
13 August 2012

What is CVE-2012-4266?

The Proman Xpress application version 5.0.1 contains a Cross-Site Scripting vulnerability located in the client_details.php file. This flaw enables remote attackers to inject arbitrary web scripts or HTML through the cl_comments parameter, potentially leading to unauthorized script execution in the context of the victim's browser. Attackers can exploit this vulnerability to manipulate user sessions, deface websites, or redirect users to malicious sites.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.