PT-2018-13708 · Cscms · Cscms

Published

2018-09-08

·

Updated

2018-10-19

·

CVE-2018-16730

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CScms version 4.1
Description The issue concerns an XSS vulnerability in the uploadpluginssysInstall.php file of CScms. This vulnerability can be exploited via the site name.
Recommendations For CScms version 4.1, update the Install.php file to properly sanitize user input for the site name to prevent XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16730

Affected Products

Cscms