Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Balvindersingh23

#50085de 53,635
4.8CVSS total
Vulnerabilidades · 1
PT-2018-10127
4.8
2018-06-14
Blackcat · Blackcat Cms · CVE-2018-10821
**Name of the Vulnerable Software and Affected Versions** BlackCatCMS version 1.3 **Description** A cross-site scripting (XSS) issue exists, allowing remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel in backend/pages/modify.php. **Recommendations** For BlackCatCMS version 1.3, as a temporary workaround, consider restricting access to the `search panel` in `backend/pages/modify.php` to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.