PT-2018-10604 · Phpmywind · Phpmywind

Ik3O

·

Publicado

2018-05-26

·

Atualizado

2018-06-27

·

CVE-2018-11487

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PHPMyWind version 5.5
Description The issue concerns a security problem where an attacker can inject malicious code. This is possible through the cid parameter to the "newsshow.php" endpoint, or the query string to the "news.php" or "about.php" endpoints.
Recommendations For PHPMyWind version 5.5, avoid using the cid parameter in the "newsshow.php" endpoint, and restrict access to the query strings in "news.php" and "about.php" until a fix is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11487

Produtos afetados

Phpmywind