A cross-site scripting vulnerability is present in Xbtit 3.1. The stored XSS vulnerability occurs because /ajaxchat/sendChatData.php does not properly validate the value of the "n" (POST) parameter. Through this vulnerability, an attacker is capable to execute malicious JavaScript code.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NBtiteam Xbtit
APPBtiteam3.1
Powiązane podatności
BTITeam XBTIT: przechowywanie haseł jako niezasalowane skróty MD5
BTITeam XBTIT: słabe hashowanie hasła w cookie umożliwia odzyskanie hasła
A blind SQL injection vulnerability exists in Xbtit 3.1 via the sid parameter in ajaxchat/getHistoryChatData.p...
An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possib...
An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable t...