PT-2018-14727 · Publiccms · Publiccms

Isecream

·

Published

2018-11-04

·

Updated

2018-12-11

·

CVE-2018-18927

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PublicCMS version 4.0
Description An issue in PublicCMS allows cross-site scripting (XSS) by modifying the page list "attached" attribute. This can be achieved through an SQL statement, such as 'UPDATE sys module SET attached = "[XSS]" WHERE id="page list"'.
Recommendations For PublicCMS version 4.0, update the page list "attached" attribute to prevent XSS attacks, ensuring that user input is properly sanitized to avoid malicious script execution. As a temporary workaround, consider restricting access to the sys module table to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18927

Affected Products

Publiccms