Cross-Site Scripting Vulnerability in Proman Xpress by Proman
CVE-2012-4266
Currently unrated
What is CVE-2012-4266?
The Proman Xpress application version 5.0.1 contains a Cross-Site Scripting vulnerability located in the client_details.php file. This flaw enables remote attackers to inject arbitrary web scripts or HTML through the cl_comments parameter, potentially leading to unauthorized script execution in the context of the victim's browser. Attackers can exploit this vulnerability to manipulate user sessions, deface websites, or redirect users to malicious sites.