PT-2018-14617 · Semcms · Semcms
Published
2018-10-28
·
Updated
2018-12-04
·
CVE-2018-18739
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SEMCMS version 3.4
Description
A cross-site scripting (XSS) issue was found in the Keywords field of the admin/SEMCMS Products.php page, specifically when the lgid parameter is set to 1.
Recommendations
For SEMCMS version 3.4, update the
SEMCMS Products.php file to properly sanitize user input in the Keywords field to prevent XSS attacks.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Semcms