PT-2018-13702 · Baijiacms+1 · Baijiacms+1

Xxy961216

·

Published

2018-09-08

·

Updated

2018-10-26

·

CVE-2018-16725

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions baijiacms version V4
Description A security issue exists in the software due to a Cross-Site Scripting (XSS) flaw. The vulnerability is exploited via the id parameter in the assets/weengine/components/zclip/ZeroClipboard.swf endpoint. This issue arises from the non-standard use of a flash component.
Recommendations For baijiacms version V4, avoid using the id parameter in the assets/weengine/components/zclip/ZeroClipboard.swf endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the ZeroClipboard.swf component to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16725

Affected Products

Zeroclipboard.Swf
Baijiacms