Multiple Cross Site Scripting (XSS) vulnerabilities exits in SEO Panel v4.8.0 via the (1) totime parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) socialmedia.php, and (j) reports.php; the (2) fromtime parameter in (a) backlinks.php, (b) analytics.php, (c) log.php, (d) overview.php, (e) pagespeed.php, (f) rank.php, (g) review.php, (h) saturationchecker.php, (i) socialmedia.php, (j) webmaster-tools.php, and (k) reports.php; the (3) ordercol parameter in (a) analytics.php, (b) review.php, (c) socialmedia.php, and (d) webmaster-tools.php; and the (4) pageno parameter in (a) alerts.php, (b) log.php, (c) keywords.php, (d) proxy.php, (e) searchengine.php, and (f) siteauditor.php.
{ "cpes": [ "cpe:2.3:a:seopanel:seo_panel:4.8.0:*:*:*:*:*:*:*" ], "severity": "Medium" }