PT-2018-13665 · Evolution Cms · Evolution Cms

Publicado

2018-12-28

·

Atualizado

2022-05-14

·

CVE-2018-16638

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Evolution CMS versions 1.4.0 through 1.4.5
Description The issue allows for XSS via the manager/ API endpoint, specifically through the search parameter. This can potentially lead to malicious script execution.
Recommendations For Evolution CMS versions 1.4.0 through 1.4.5, update to version 1.4.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the manager/ API endpoint until the update is applied. Avoid using the search parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16638
GHSA-9MFC-GR8C-XJ4M

Produtos afetados

Evolution Cms