PT-2018-18076 · Mojoportal · Mojoportal
P3Core0Ath
+1
·
Published
2018-02-24
·
Updated
2024-08-05
·
CVE-2018-7447
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mojoPortal versions prior to 2.6.0.0
Description
The issue arises from the software's failure to sanitize user-supplied input, leading to multiple persistent cross-site scripting vulnerabilities. Specifically, the
Title and Subtitle fields of the 'Blog' page are vulnerable. It's worth noting that the software maintainer disputes this as a vulnerability, citing that the fields in question are only accessible to administrators who are supposed to have access to add scripts.Recommendations
For versions prior to 2.6.0.0, as a temporary workaround, consider restricting access to the
Title and Subtitle fields of the 'Blog' page to minimize the risk of exploitation. Additionally, ensure that only trusted administrators have access to these fields, as they are intended for users who should have the capability to add scripts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mojoportal