PT-2018-9875 · Hongcms · Hongcms
Starnightcyber
·
Published
2018-04-26
·
Updated
2018-05-25
·
CVE-2018-10422
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
HongCMS version 3.0.0
Description:
An issue was discovered in the post news feature, which has Stored XSS via the
content field.Recommendations:
For HongCMS version 3.0.0, update to a newer version that contains a fix for this issue, or as a temporary workaround, consider validating and sanitizing user input in the
content field to prevent XSS attacks.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hongcms