PT-2018-16807 · Fork Cms · Fork Cms

Published

2018-01-04

·

Updated

2022-05-14

·

CVE-2018-5215

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fork CMS version 5.0.7
Description The issue concerns a cross-site scripting (XSS) problem. It is located in the /private/en/pages/edit API endpoint, specifically via the title parameter.
Recommendations For Fork CMS version 5.0.7, as a temporary workaround, consider restricting access to the /private/en/pages/edit endpoint until a patch is available. Avoid using the title parameter in this endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5215
GHSA-8FJQ-CPR7-CMFP

Affected Products

Fork Cms