PT-2018-16176 · Sexstatic · Sexstatic

Bl4De

+1

·

Published

2018-06-01

·

Updated

2023-02-28

·

CVE-2018-3755

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions sexstatic versions 0.6.2 and earlier sexstatic (all versions)
Description The issue allows for stored cross-site scripting (XSS) if an attacker can control a filename served by the software. This can lead to HTML injection in directory names, resulting in Stored XSS when a malicious file is embedded with an iframe element used in the directory name.
Recommendations For sexstatic versions 0.6.2 and earlier, there is no information about a newer version that contains a fix for this issue. For sexstatic (all versions), do not install or use this module at this time, as there is currently no fix available for this issue.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2018-3755
GHSA-QFH2-6F7Q-GR86

Affected Products

Sexstatic