PT-2019-8869 · Clippercms · Clippercms
Prasadlingamaiah
·
Published
2019-08-15
·
Updated
2019-08-26
·
CVE-2018-12101
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CMS Clipper version 1.3.3
Description
The issue concerns a security problem where an attacker can inject malicious code. This is possible due to insufficient input validation in several fields, including the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.
Recommendations
For CMS Clipper version 1.3.3, update to a version that addresses this issue, as the current version allows for malicious code injection in the specified fields. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clippercms