PT-2018-10117 · Frog Cms · Frog Cms
Black-Lo
·
Published
2018-05-08
·
Updated
2020-08-24
·
CVE-2018-10806
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Frog CMS version 0.9.5
Description
A reflected Cross Site Scripting issue was found, which can be exploited via the
file[current name] parameter to the "admin/?/plugin/file manager/rename" URI. This issue can be used in conjunction with a CSRF attack.Recommendations
For Frog CMS version 0.9.5, avoid using the
file[current name] parameter in the "admin/?/plugin/file manager/rename" URI until the issue is resolved. As a temporary workaround, consider restricting access to the file manager plugin to minimize the risk of exploitation.Exploit
Fix
CSRF
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Frog Cms