Cross-Site Scripting Vulnerability in PhreeBooksERP by PhreeBooks
CVE-2017-5990
6.1MEDIUM
What is CVE-2017-5990?
A vulnerability in PhreeBooksERP allows attackers to exploit insufficient filtering of user inputs, specifically in the 'form' HTTP GET parameter. This weakness can lead to the execution of arbitrary HTML and script code in a user's browser under the context of the affected website. The issue is present in certain URLs related to shipping method extensions. Note that these specific files are not included in the stable release version of the software, thus emphasizing the importance of using updated versions to mitigate potential risks.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
