What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar Random Banner random-banner allows DOM-Based XSS.This issue affects Random Banner: from n/a through <= 4.2.12.
Explanation of Vulnerability in Simple Terms
02Summary
Random Banner versions 4.2.12 and earlier contain a cross-site scripting (XSS) vulnerability in banner content handling. An authenticated administrator with high privileges can inject malicious scripts that execute in the browsers of users who view the banner. The vulnerability requires user interaction and affects the integrity and confidentiality of site data.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that run in visitors' browsers when they view the banner.
Potential impact on your site
04Site Impact
Malicious admins can steal visitor data, redirect users, or deface banner content without detection.
Conditions required to exploit
05Prerequisites
Attacker must have high-level admin privileges and the victim must view the affected banner.
Key dates
06Disclosure timeline
June 1, 2024
CVE published
April 28, 2026
Record updated