PT-2018-13854 · Minicms · Minicms
Glo0M7
·
Published
2018-09-14
·
Updated
2018-11-08
·
CVE-2018-17039
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
MiniCMS version 1.10
Description
The issue allows for XSS via a crafted URI due to the mishandling of $ SERVER['REQUEST URI'] when Internet Explorer is used.
Recommendations
For MiniCMS version 1.10, consider validating and sanitizing user input to prevent the exploitation of this issue, specifically when handling the
REQUEST URI variable. As a temporary workaround, restrict access to the application when using Internet Explorer until a proper fix is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minicms