What the vulnerability does
01Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS vulnerability in Bill Minozzi Car Dealer allows Code Injection.This issue affects Car Dealer: from n/a through 4.15.
Explanation of Vulnerability in Simple Terms
Car Dealer versions up to 4.15 contain a low-severity integrity issue affecting high-privilege users. An authenticated administrator can modify data in limited ways due to improper input validation. The vulnerability requires high-level account access and does not affect confidentiality or availability. Update to a version newer than 4.15 when available.
What an attacker can do
Modify site data if they have high-level administrative access.
Potential impact on your site
A compromised admin account could make unauthorized data changes; monitor admin activity and enforce strong passwords.
Conditions required to exploit
Attacker must have high-privilege (administrator-level) account on the site.
Key dates
External resources
Related vulnerabilities