PT-2026-48266 · Evoluted · Directory Listing Script
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Evoluted PHP Directory Listing Script versions prior to 4.0.6
Description
A reflected cross-site scripting issue exists in the 'index.php' endpoint. The
dir parameter is reflected without HTML encoding within the HTML title element and the anchor href attributes of the breadcrumb navigation. This allows attackers to execute arbitrary JavaScript in a victim's browser by breaking out of the title context or injecting event handlers into the breadcrumb anchor attributes.Recommendations
Update to a version newer than 4.0.5.
As a temporary mitigation, avoid using the
dir parameter in the 'index.php' endpoint.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directory Listing Script