Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
Threat-Mapped Scoring
Score: 0.0
Priority: Unclassified
EPSS
Score: 0.01884 Percentile:
0.82367
CVSS Scoring
CVSS v2 Score: 4.3
Severity:
Mapped CWE(s)
CWE-79
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')