PT-2018-12482 · Joyplus · Joyplus-Cms
Published
2018-07-18
·
Updated
2018-09-12
·
CVE-2018-14388
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
joyplus-cms version 1.6.0
Description
The issue allows for XSS via the "manager/admin ajax.php" API endpoint, specifically through the
can search device array parameter.Recommendations
For joyplus-cms version 1.6.0, consider restricting access to the
can search device array parameter in the "manager/admin ajax.php" API endpoint until a patch is available. As a temporary workaround, avoid using the can search device parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Joyplus-Cms