PT-2019-9804 · Plikli · Plikli Cms

Daniel Bishtawi

·

Published

2019-01-03

·

Updated

2019-01-14

·

CVE-2018-19414

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Plikli CMS version 4.0.0
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via specific parameters in various PHP files. The affected parameters include the keyword parameter to "groups.php", the username parameter to "login.php", and the date parameter to "search.php".
Recommendations For Plikli CMS version 4.0.0, consider disabling access to the affected PHP files, specifically "groups.php", "login.php", and "search.php", until a patch is available. Restrict input for the keyword, username, and date parameters to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19414

Affected Products

Plikli Cms