PT-2019-8869 · Clippercms · Clippercms

Prasadlingamaiah

·

Published

2019-08-15

·

Updated

2019-08-26

·

CVE-2018-12101

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CMS Clipper version 1.3.3
Description The issue concerns a security problem where an attacker can inject malicious code. This is possible due to insufficient input validation in several fields, including the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.
Recommendations For CMS Clipper version 1.3.3, update to a version that addresses this issue, as the current version allows for malicious code injection in the specified fields. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-12101

Affected Products

Clippercms