PT-2018-14221 · Navigate · Navigate Cms

Rafael Fontes Souza

·

Publicado

2018-10-04

·

Atualizado

2018-11-19

·

CVE-2018-17849

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Navigate CMS version 2.8
Description The issue concerns a Stored XSS vulnerability. It can be exploited via a request to the "navigate upload.php" endpoint, also known as File Upload, using a multipart/form-data JavaScript payload.
Recommendations For Navigate CMS version 2.8, consider disabling the file upload functionality temporarily to mitigate the risk of exploitation until a patch is available. Restrict access to the navigate upload.php endpoint to minimize the risk of Stored XSS attacks.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17849

Produtos afetados

Navigate Cms