Reflected Cross-Site Scripting Vulnerability in Userscape HelpSpot

Reflected Cross-Site Scripting Vulnerability in Userscape HelpSpot

CVE-2017-16755 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

An issue was discovered in Userscape HelpSpot before 4.7.2. A reflected cross-site scripting vulnerability exists in the "return" parameter of the "index.php?pg=moderated" endpoint. It executes when the return link is clicked.

Learn more about our User Device Pen Test.