PT-2018-19155 · Frog Cms · Frog Cms
Prafull Agarwal
+1
·
Published
2018-04-11
·
Updated
2018-05-11
·
CVE-2018-9992
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Frog CMS version 0.9.5
Description
The issue concerns a security problem where an attacker can inject malicious code. This is possible through the
name field when creating a new "File" or "Directory" on the admin screen, specifically at the "plugin/file manager/browse/" endpoint.Recommendations
For Frog CMS version 0.9.5, as a temporary workaround, consider restricting access to the
plugin/file manager/browse/ endpoint until a patch is available. Avoid using the name field in the affected endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frog Cms