Cross-Site Scripting Vulnerability in PHP Scripts Mall Advanced Real Estate Script
CVE-2019-20336

6.1MEDIUM

What is CVE-2019-20336?

In version 4.0.9 of the Advanced Real Estate Script by PHP Scripts Mall, a Cross-Site Scripting vulnerability has been identified in the search-results.php file. The vulnerability is specifically associated with the 'searchtext' parameter, which allows an attacker to inject malicious scripts. This can lead to unauthorized actions being performed on behalf of users and unauthorized access to sensitive information, highlighting the importance of addressing such security flaws in web applications.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.