PT-2018-14419 · Kaasoft · Kaasoft Library Cms
Published
2018-10-17
·
Updated
2018-12-03
·
CVE-2018-18372
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
KAASoft Library CMS - Powerful Book Management System version 2.1.1
Description
A Stored XSS issue has been found, allowing potential exploitation via the "/admin/book/create/" endpoint, specifically through the
title parameter.Recommendations
For KAASoft Library CMS - Powerful Book Management System version 2.1.1, consider restricting access to the
/admin/book/create/ endpoint until a fix is available, and avoid using the title parameter in this endpoint to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kaasoft Library Cms