Description
WEBIGniter 28.7.23 contains a cross-site scripting vulnerability in the user creation process that allows unauthenticated attackers to execute malicious JavaScript code, enabling potential XSS attacks.
Problem types
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
28.7.23
Credits
RedTeamer IT Security, Mesut Cetin
References
www.exploit-db.com/exploits/51900 (ExploitDB-51900)
webigniter.net/ (Official WEBIGniter Homepage)
webigniter.net/demo (WEBIGniter Demo Page)
www.vulncheck.com/...-scripting-xss-in-user-creation-process