invernyx/smartcars-3-bugs

invernyx/smartcars-3-bugs

Releases0
Stars5
The bug tracker for the smartCARS 3 application

CVE History

CVEPublishedCVSS v3CVSS v2
5.4 MEDIUM

A stored cross-site scripting (XSS) vulnerability in TFDi Design smartCARS 3 v0.7.0 and below allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the body of news article.

8 HIGH

smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in error logs. This problem doesn't occur in version 0.5.9. As a workaround, delete the affected log file, and ensure one logs in correctly.