PT-2018-12812 · My Little Forum · My Little Forum

Published

2018-08-05

·

Updated

2024-02-14

·

CVE-2018-14937

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions my little forum version 2.4.12
Description The issue allows for XSS via the Menu Link field in the Add page option.
Recommendations For my little forum version 2.4.12, consider restricting access to the Add page option until a fix is available, and avoid using the Menu Link field to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2018-14937

Affected Products

My Little Forum