Stored Cross Site Scripting in SmarterStats by Insightful Corporation
CVE-2017-14620
6.1MEDIUM
What is CVE-2017-14620?
An identified vulnerability in SmarterStats Version 11.3.6347 allows for the manipulation of HTTP log files, specifically rendering the Referer field from the URL /Data/Reports/ReferringURLsWithQueries. This flaw enables an attacker to inject malicious scripts, which are then stored and can be triggered when users access those logs, leading to potential unauthorized actions and data exposure.