esoTalk CMS Comment Field Cross Site Scripting Vulnerability
BID:71194
Info
esoTalk CMS Comment Field Cross Site Scripting Vulnerability
| Bugtraq ID: | 71194 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 19 2014 12:00AM |
| Updated: | Nov 19 2014 12:00AM |
| Credit: | Evi1m0 |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
esoTalk CMS Comment Field Cross Site Scripting Vulnerability
esoTalk is prone to a cross-site-scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
esoTalk 1.0.0g4 is vulnerable.
esoTalk is prone to a cross-site-scripting vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
esoTalk 1.0.0g4 is vulnerable.
References
esoTalk CMS Comment Field Cross Site Scripting Vulnerability
References:
References:
- esoTalk CMS Homepage (esoTalk)
- Esotalk topic xss vulnerability (Hackersoul)