PT-2018-13992 · Weaselcms · Weaselcms

Cbiuo

·

Published

2018-09-23

·

Updated

2018-11-09

·

CVE-2018-17361

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WeaselCMS version 0.3.6
Description The issue allows remote attackers to inject arbitrary web script or HTML via the PATH INFO to index.php because $ SERVER['PHP SELF'] is mishandled. This can be exploited by sending a malicious request to the "index.php" endpoint.
Recommendations For WeaselCMS version 0.3.6, update to a version where the handling of $ SERVER['PHP SELF'] is corrected to prevent the injection of arbitrary web script or HTML. As a temporary workaround, consider validating and sanitizing the PATH INFO to prevent malicious input.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17361

Affected Products

Weaselcms