|
YA Book City Field HTML-injection Vulnerability
YA Book is prone to an HTML-injection vulnerability because it fails to sufficiently sanitize user-supplied input before displaying it in dynamically generated content. An attacker could exploit this vulnerability to execute arbitrary script code in the browser of an unsuspecting victim in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. YA Book 0.98-alpha is vulnerable to this issue; prior versions may also be affected. |
|
Privacy Statement |