PT-2018-14971 · Articlecms · Articlecms
Langyayue
·
Published
2018-11-23
·
Updated
2018-12-19
·
CVE-2018-19469
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ArticleCMS versions prior to 2017-02-19
Description
The issue allows for XSS attacks via the "/update personal infomation" API endpoint, specifically through the
realname or email parameters.Recommendations
For ArticleCMS versions prior to 2017-02-19, avoid using the
realname and email parameters in the "/update personal infomation" endpoint until a fix is available. As a temporary workaround, consider restricting access to this endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Articlecms