PT-2018-13981 · Ucms · Ucms
Published
2018-09-21
·
Updated
2018-11-13
·
CVE-2018-17320
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
UCMS version 1.4.6
Description
An issue was discovered in the software, where the
minfo parameter in the sadmin/aindex.php endpoint is vulnerable to stored XSS in the sadmin aaddpost action.Recommendations
For UCMS version 1.4.6, avoid using the
minfo parameter in the sadmin/aindex.php endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the aaddpost.php file to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ucms