PT-2022-8061 · Unknown · Jmpotato Pomash

·

CVE-2018-25051

·

Published

2022-12-28

·

Updated

2024-05-17

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions JmPotato Pomash (affected versions not specified)
Description A problematic vulnerability was found in JmPotato Pomash, affecting an unknown part of the file Pomash/theme/clean/templates/editor.html. The manipulation of the article.title, content.title, or article.tag arguments leads to cross-site scripting. It is possible to initiate the attack remotely.
Recommendations To fix this issue, it is recommended to apply a patch with the name be1914ef0a6808e00f51618b2de92496a3604415. As a temporary workaround, consider restricting the manipulation of the article.title, content.title, and article.tag arguments to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25051

Affected Products

Jmpotato Pomash