GigToDo Freelance Marketplace Script 1.3 Persistent XSS
Vulnerability Description
GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers can craft XSS payloads in the create_proposal endpoint that execute when administrators or other users view the stored proposal, enabling cookie theft and malicious redirects.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25739
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- m0ze
Affected Vendor
Gigtodoscript
View all reports →