MyWebSQL version 3.6 is vulnerable to stored XSS in the database manager component resulting in account takeover or stealing of information
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NMywebsql
APPMywebsql3.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
Related vulnerabilities
CVE-2019-7731CRITICAL9.8PL ✓same product
RCE w MyWebSQL 3.7 poprzez funkcję Backup Database
CVE-2019-7730MEDIUM5.7same product
MyWebSQL 3.7 has a Cross-site request forgery (CSRF) vulnerability for deleting a database via the /?q=wrkfrm&...
CVE-2019-7544MEDIUM5.4same product
An issue was discovered in MyWebSQL 3.7. The Add User function of the User Manager pages has a Stored Cross-si...
CVE-2014-4735MEDIUM4.3same product
Cross-site scripting (XSS) vulnerability in MyWebSQL 3.4 and earlier allows remote attackers to inject arbitra...