PT-2018-13861 · Cqu · Cqu-Lankers
Xxy961216
·
Published
2018-09-14
·
Updated
2018-11-09
·
CVE-2018-17049
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CQU-LANKERS through 2017-11-02
Description
The issue is related to a security problem where an attacker can execute malicious scripts. This is achieved by exploiting the
callback parameter in the "public/api.php" endpoint, specifically in an uploadpic action.Recommendations
For CQU-LANKERS through 2017-11-02, avoid using the
callback parameter in the "public/api.php" endpoint for the uploadpic action until a fix is available. As a temporary workaround, consider restricting access to the uploadpic action to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cqu-Lankers