PT-2026-102307 · Unknown · Av Book Library
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Book Library (Free) versions prior to 6.4.6
Description
Reflected Cross-Site Scripting occurs in the public book-detail page template located at site/views/view book/tmpl/default.php. The application echoes the raw
title request parameter directly into a double-quoted HTML attribute without using any escaping functions. An attacker can provide a value containing a double quote to close the attribute prematurely, allowing the execution of arbitrary HTML or JavaScript.Recommendations
Update Book Library (Free) to version 6.4.6 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Av Book Library