In the "bestinformed Web" application, some user input...
Moderate severity
Unreviewed
Published
Feb 18, 2025
to the GitHub Advisory Database
•
Updated Feb 18, 2025
Description
Published by the National Vulnerability Database
Feb 18, 2025
Published to the GitHub Advisory Database
Feb 18, 2025
Last updated
Feb 18, 2025
In the "bestinformed Web" application, some user input was not properly sanitized. This leads to multiple unauthenticated stored cross-site scripting vulnerabilities. An unauthenticated attacker is able to compromise the sessions of users on the server by injecting JavaScript code into their session using an "Unauthenticated Stored Cross-Site Scripting". The attacker is then able to ride the session of those users and can abuse their privileges on the "bestinformed Web" application.
References