Waimai · Waimai Super Cms · CVE-2018-18261
**Name of the Vulnerable Software and Affected Versions**
waimai Super Cms version 20150505
**Description**
The issue is related to an XSS vulnerability. It can be exploited via the "/admin.php/Foodcat/addsave" API endpoint, specifically through the `fcname` parameter.
**Recommendations**
For waimai Super Cms version 20150505, avoid using the `fcname` parameter in the "/admin.php/Foodcat/addsave" API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.