What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR allows Reflected XSS.This issue affects BEAR: from n/a through 1.1.4.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in realmag777 BEAR allows Reflected XSS.This issue affects BEAR: from n/a through 1.1.4.2.
Explanation of Vulnerability in Simple Terms
BEAR contains a cross-site scripting (XSS) vulnerability that allows an attacker to inject malicious scripts into the application. The vulnerability affects versions up to 1.1.4.2 and requires user interaction to exploit. An attacker can execute arbitrary JavaScript in a victim's browser, potentially stealing session data or performing actions on their behalf.
What an attacker can do
Execute JavaScript code in a victim's browser to steal data or perform unauthorized actions.
Potential impact on your site
Users visiting the site could have their sessions hijacked or personal data stolen through injected scripts.
Conditions required to exploit
Victim must click a malicious link or visit an attacker-controlled page that triggers the vulnerability.
Key dates
External resources
Related vulnerabilities