Stored XSS in PHP Scripts Mall Personal Video Collection Script
CVE-2019-9606

5.4MEDIUM

What is CVE-2019-9606?

The Personal Video Collection Script version 4.0.4 from PHP Scripts Mall contains a vulnerability that allows attackers to exploit the 'Update profile' feature, resulting in stored cross-site scripting (XSS). This can lead to unauthorized scripts being executed in users' browsers, which may compromise user data and lead to further attacks. It is essential for users to ensure they update to secure versions and adopt best practices to mitigate such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.