Phpok · Phpok · CVE-2018-20006
**Name of the Vulnerable Software and Affected Versions**
PHPok version 5.0.055
**Description**
A Stored XSS issue was found, which can be exploited via the `title` parameter to the "api.php?c=post&f=save" API endpoint, accessible through the "index.php?id=book" URI.
**Recommendations**
For PHPok version 5.0.055, as a temporary workaround, consider restricting access to the "api.php?c=post&f=save" API endpoint until a patch is available. Avoid using the `title` parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.