XSS Vulnerability in PHP Scripts Mall Advanced Real Estate Script
CVE-2018-15189

5.4MEDIUM

What is CVE-2018-15189?

The advanced-real-estate-script by PHP Scripts Mall is susceptible to a cross-site scripting (XSS) vulnerability. This flaw arises from improper handling of user input in the 'Name' field of user profiles, allowing attackers to inject malicious scripts. If successfully exploited, this could lead to unauthorized access to sensitive information or misuse of the affected application, highlighting the need for prompt remediation to protect users.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.