What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagniGenie RestroPress allows Stored XSS.This issue affects RestroPress: from n/a through 3.1.2.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagniGenie RestroPress allows Stored XSS.This issue affects RestroPress: from n/a through 3.1.2.1.
Explanation of Vulnerability in Simple Terms
RestroPress versions up to 3.1.2.1 contain a cross-site scripting vulnerability that allows attackers to inject malicious scripts. An authenticated user with low privileges can craft a request that, when visited by another user, executes arbitrary JavaScript in their browser. The vulnerability affects the site's integrity and confidentiality. Update to version 3.3 or later to resolve this issue.
What an attacker can do
Inject and execute malicious JavaScript in other users' browsers to steal data or perform actions on their behalf.
Potential impact on your site
Authenticated attackers can compromise user sessions, steal credentials, or deface content visible to other users.
Conditions required to exploit
Attacker needs a low-privilege account on the site; victim must visit a malicious link or page.
Key dates
External resources
Related vulnerabilities