PT-2019-15284 · Sitemagic · Sitemagic Cms
Alessandro Magnosi
+1
·
Published
2019-10-23
·
Updated
2019-10-24
·
CVE-2019-18219
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Sitemagic CMS version 4.4.1
Description
The issue is related to a Cross-Site-Scripting (XSS) vulnerability due to the failure to validate user input. This allows for JavaScript injection within both GET or POST requests. The affected components are index.php and upgrade.php, where the injection can occur via a crafted URL or via the
UpgradeMode POST parameter.Recommendations
For Sitemagic CMS version 4.4.1, consider validating user input to prevent JavaScript injection, and restrict access to the index.php and upgrade.php components until a fix is available. As a temporary workaround, avoid using the
UpgradeMode parameter in POST requests to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sitemagic Cms