PT-2018-14727 · Publiccms · Publiccms
Isecream
·
Published
2018-11-04
·
Updated
2018-12-11
·
CVE-2018-18927
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PublicCMS version 4.0
Description
An issue in PublicCMS allows cross-site scripting (XSS) by modifying the
page list "attached" attribute. This can be achieved through an SQL statement, such as 'UPDATE sys module SET attached = "[XSS]" WHERE id="page list"'.Recommendations
For PublicCMS version 4.0, update the
page list "attached" attribute to prevent XSS attacks, ensuring that user input is properly sanitized to avoid malicious script execution. As a temporary workaround, consider restricting access to the sys module table to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Publiccms