045 – HTML code injection
Description
The applications fields allow the injection of HTML code. This could enable attackers to modify the applications appearance in order to trick its users into performing undesired actions.
Impact
- Allow an attacker to modify the page. - Craft malicious links, including his injected HTML content, and sends it to a user via email.
Recommendation
Filter the information that comes from text fields with regular expressions or white lists to avoid injections.
Threat
Authenticated attacker from the Internet.
Expected Remediation Time
Score 4.0
Default score using CVSS 4.0. It may change depending on the context of the src.
Base 4.0
- Attack vector: N
- Attack complexity: L
- Attack Requirements: N
- Privileges required: L
- User interaction: N
- Confidentiality (VC): N
- Integrity (VI): L
- Availability (VA): N
- Confidentiality (SC): L
- Integrity (SI): L
- Availability (SA): L
Threat 4.0
- Exploit maturity: P