PT-2017-18521 · Genixcms · Genixcms
Fgeek
·
Published
2017-05-04
·
Updated
2022-05-17
·
CVE-2017-8780
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GeniXCMS version 1.0.2
Description
The issue is triggered by a comment that is mishandled during a publish operation by an administrator. This can be demonstrated by a malformed P element, leading to a cross-site scripting (XSS) issue.
Recommendations
For GeniXCMS version 1.0.2, consider disabling the comment publishing feature for administrators until a patch is available to prevent potential exploitation. Restrict access to the publish operation to minimize the risk of XSS attacks.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Genixcms