PT-2018-13854 · Minicms · Minicms

Glo0M7

·

Published

2018-09-14

·

Updated

2018-11-08

·

CVE-2018-17039

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MiniCMS version 1.10
Description The issue allows for XSS via a crafted URI due to the mishandling of $ SERVER['REQUEST URI'] when Internet Explorer is used.
Recommendations For MiniCMS version 1.10, consider validating and sanitizing user input to prevent the exploitation of this issue, specifically when handling the REQUEST URI variable. As a temporary workaround, restrict access to the application when using Internet Explorer until a proper fix is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17039

Affected Products

Minicms