Description
|
|
Multiple vulnerabilities have been identified in Jetbox CMS, which could be exploited by attackers to execute arbitrary scripting code or send arbitrary email messages via a vulnerable server.
The first issue is caused by input validation errors in various modules (e.g. "search" or "supplynews") when processing user-supplied parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.
The second vulnerability is caused by missing authentication checks within the "formmail.php" script, which could be exploited by attackers to send spam messages through the application.
|