PT-2018-13854 · Minicms · Minicms
Glo0M7
·
Publicado
2018-09-14
·
Atualizado
2018-11-08
·
CVE-2018-17039
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MiniCMS version 1.10
Description
The issue allows for XSS via a crafted URI due to the mishandling of $ SERVER['REQUEST URI'] when Internet Explorer is used.
Recommendations
For MiniCMS version 1.10, consider validating and sanitizing user input to prevent the exploitation of this issue, specifically when handling the
REQUEST URI variable. As a temporary workaround, restrict access to the application when using Internet Explorer until a proper fix is applied.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Minicms