Multiple cross-site scripting (XSS) vulnerabilities in Havalite 1.0.4 and previous versions allow remote malicious users to inject arbitrary web script or HTML via the (1) find or (2) replace fields to havalite/findReplace.php; (3) username parameter to havalite/hava_login.php, (4) the Edit Article module, or (5) hava_post.php in the postAuthor module; (6) postId parameter to hava_post.php; (7) userId parameter to hava_user.php; or (8) linkId parameter to hava_link.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
havalite cms |