PT-2019-19364 · Wuzhi · Wuzhi Cms

Redey3

·

Published

2019-02-25

·

Updated

2019-02-25

·

CVE-2019-9110

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WUZHI CMS version 4.1.0
Description A security issue exists where an XSS attack can be performed. The issue is related to the "index.php?m=content&f=postinfo&v=listing&set iframe=" API endpoint, which is connected to the coreframe/app/content/postinfo.php file.
Recommendations For WUZHI CMS version 4.1.0, as a temporary workaround, consider restricting access to the "index.php?m=content&f=postinfo&v=listing&set iframe=" endpoint until a patch is available. Avoid using the set iframe parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-9110

Affected Products

Wuzhi Cms