PT-2019-9284 · Creatiwity · Creatiwity Witycms
Twohub
·
Published
2019-06-20
·
Updated
2019-06-21
·
CVE-2018-16250
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Creatiwity wityCMS version 0.6.2
Description
The issue concerns the "utilisateur" menu in Creatiwity wityCMS, where two input points for user information are vulnerable to XSS attacks. Specifically, the
first name and last name parameters are affected.Recommendations
For Creatiwity wityCMS version 0.6.2, consider restricting input for the
first name and last name parameters to minimize the risk of XSS exploitation. As a temporary workaround, validate and sanitize user input for these parameters until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Creatiwity Witycms