PT-2018-14417 · Nc · Nc-Cms

Published

2018-10-15

·

Updated

2018-12-03

·

CVE-2018-18361

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions nc-cms versions prior to 2017-03-10
Description An issue was discovered that allows XSS via the name parameter in the "index.php?action=edit html" endpoint. This is demonstrated by a value beginning with 'home content' and containing a crafted SRC attribute of an IMG element.
Recommendations For versions prior to 2017-03-10, avoid using the name parameter in the "index.php?action=edit html" endpoint until the issue is resolved. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18361

Affected Products

Nc-Cms