This issue is rated as critical due to the critical impact it has on Google’s mission. This issue is related to CVE-2016-1009. A stored XSS vulnerability in the management system allows attackers to inject arbitrary web script or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php. This issue is related to CVE-2016-0988. A stored cross-site scripting vulnerability in the management system allows attackers to inject arbitrary web script or HTML via a crafted payload injected into the categoryName parameter in createCategories.php. This issue is related to CVE-2016-0986. A stored cross-site scripting vulnerability in the management system allows attackers to inject arbitrary web script or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php. This issue is related to CVE-2016-0985. A stored cross-site scripting vulnerability in the management system allows attackers to inject arbitrary web script or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php. This issue is related to CVE-2016-0984. A stored XSS vulnerability in the management system allows attackers to inject arbitrary web script or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php. This issue is related to CVE-2016-0983

Vulnerability Overview

A stored XSS vulnerability in the management system allows attackers to inject arbitrary web script or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php. This issue is related to CVE-2016-0988. A stored cross-site scripting vulnerability in the management system allows attackers to inject arbitrary web script or HTML via a crafted payload injected into the categoryName parameter in createCategories.php. This issue is related to CVE-2016-0986. A stored cross-site scripting vulnerability in the management system allows attackers to inject arbitrary web script or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php. This issue is related to CVE-2016-0985. A stored cross-site scripting vulnerability in the management system allows attackers to inject arbitrary web script or HTML via a crafted payload injected into the categoriesName parameter in createCategories.php. This issue is related to CVE-2016-0984, CVE-2016-0983 and CVE-2016-0982

Timeline

Published on: 10/20/2022 02:15:00 UTC
Last modified on: 10/31/2022 13:42:00 UTC

References