PT-2018-14855 · Xiaocms · Xiaocms
Published
2018-11-12
·
Updated
2018-12-13
·
CVE-2018-19195
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
XiaoCms version 20141229
Description
An issue was discovered related to XSS in the template/default/show product.html file.
Recommendations
For XiaoCms version 20141229, consider restricting access to the template/default/show product.html file until a fix is available. As a temporary workaround, review and sanitize any user-input data processed by this template to minimize the risk of XSS exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xiaocms