PT-2022-7930 · Unknown · Elefant Cms

Tim Coen

·

Published

2022-06-20

·

Updated

2022-06-28

·

CVE-2017-20057

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Elefant CMS version 1.3.12-RC
Description A problematic vulnerability has been found in Elefant CMS. The issue is related to the manipulation of the username argument, which leads to basic cross-site scripting (Persistent). This can be launched remotely.
Recommendations For Elefant CMS version 1.3.12-RC, upgrade to version 1.3.13 to address this issue. As a temporary workaround, consider restricting the use of the username argument until the upgrade is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20057
GHSA-XWJ7-29J7-RW76

Affected Products

Elefant Cms