Home
Description
Reflected Cross Site Scripting (XSS) vulnerabilities in GDTaller. These vulnerabilities allows an attacker execute JavaScript code in the victim’s browser by sending a malicious URL en ‘site’ parameter in ‘app_login.php’.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or ‘Cross-site Scripting’)
Product status
Any version before *
References
www.incibe.es/…ces/aviso/multiple-vulnerabilities-gdtaller
