What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Sitekit sitekit allows Stored XSS.This issue affects Sitekit: from n/a through <= 1.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webvitaly Sitekit sitekit allows Stored XSS.This issue affects Sitekit: from n/a through <= 1.9.
Explanation of Vulnerability in Simple Terms
Sitekit versions 1.9 and earlier contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. The vulnerability requires user interaction and affects the integrity and confidentiality of site data. Sites running Sitekit 1.9 or earlier should update to version 2.0 or later.
What an attacker can do
Inject malicious scripts that execute in other users' browsers and steal or modify site data.
Potential impact on your site
Authenticated attackers can compromise user sessions, steal credentials, or deface site content visible to other users.
Conditions required to exploit
Attacker must have a low-privilege account and trick a user into visiting a malicious link or page.
Key dates
External resources
Related vulnerabilities