logo

Database

Description

It is possible to inject JavaScript into application fields, with the goal of having the server execute malicious code before rendering user input. This allows a remote attacker to compromise internal server files, make requests on behalf of the server or perform a port scan.

Impact

- Extracting information from the server. - Execute actions on the server or on behalf of the server.

Recommendation

Properly sanitize user input, before executing it on the server side.

Threat

Unprivileged attacker from the internet impersonating the application.

Expected Remediation Time

⏱️ 45 minutes.