What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Stored XSS.This issue affects Z Y N I T H: from n/a through 7.4.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VIICTORY MEDIA LLC Z Y N I T H allows Stored XSS.This issue affects Z Y N I T H: from n/a through 7.4.9.
Explanation of Vulnerability in Simple Terms
Z Y N I T H versions up to 7.4.9 contain a cross-site scripting vulnerability that allows attackers to inject malicious scripts without authentication. The vulnerability can be exploited remotely over the network without user interaction. Attackers can read sensitive data, modify site content, and disrupt availability. Update to a version newer than 7.4.9 immediately.
What an attacker can do
Inject malicious scripts to steal data, modify content, or disrupt the site without needing to log in.
Potential impact on your site
Attackers can compromise visitor sessions, deface content, and cause service disruption without any warning or user action.
Conditions required to exploit
Network access to the vulnerable Z Y N I T H instance; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities