PT-2019-9284 · Creatiwity · Creatiwity Witycms

Twohub

·

Published

2019-06-20

·

Updated

2019-06-21

·

CVE-2018-16250

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Creatiwity wityCMS version 0.6.2
Description The issue concerns the "utilisateur" menu in Creatiwity wityCMS, where two input points for user information are vulnerable to XSS attacks. Specifically, the first name and last name parameters are affected.
Recommendations For Creatiwity wityCMS version 0.6.2, consider restricting input for the first name and last name parameters to minimize the risk of XSS exploitation. As a temporary workaround, validate and sanitize user input for these parameters until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16250

Affected Products

Creatiwity Witycms