Description
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.
References
https://github.com/microweber/microweber/commit/f20abf30a1d9c1426c5fb757ac63998dc5b92bfc
https://huntr.dev/bounties/747c2924-95ca-4311-9e69-58ee0fb440a0
https://github.com/microweber/microweber/commit/f20abf30a1d9c1426c5fb757ac63998dc5b92bfc
https://huntr.dev/bounties/747c2924-95ca-4311-9e69-58ee0fb440a0
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 · Medium
Information
Source identifier
Vulnerability status
Modified
Published
2022-09-20T12:15:09.783Z
3 years agoLast modified
2024-11-21T06:19:08.013Z
1 year ago