PT-2018-13854 · Minicms · Minicms

Glo0M7

·

Publicado

2018-09-14

·

Atualizado

2018-11-08

·

CVE-2018-17039

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MiniCMS version 1.10
Description The issue allows for XSS via a crafted URI due to the mishandling of $ SERVER['REQUEST URI'] when Internet Explorer is used.
Recommendations For MiniCMS version 1.10, consider validating and sanitizing user input to prevent the exploitation of this issue, specifically when handling the REQUEST URI variable. As a temporary workaround, restrict access to the application when using Internet Explorer until a proper fix is applied.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17039

Produtos afetados

Minicms