PT-2018-15323 · Wst · Wstmart

Denyorallow

·

Published

2018-12-22

·

Updated

2019-01-29

·

CVE-2018-20367

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WSTMart version 2.0.8 181212
Description The issue concerns a stored XSS in the "mall some commodity details: commodity consultation" component. This occurs via the consultContent parameter, as demonstrated by the "/home/goodsconsult/add.html" API endpoint in the index.php file.
Recommendations For WSTMart version 2.0.8 181212, consider restricting access to the consultContent parameter in the "/home/goodsconsult/add.html" API endpoint to minimize the risk of exploitation. Avoid using the consultContent parameter until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20367

Affected Products

Wstmart