Stored Cross-Site Scripting in WolfCMS by Wolf
CVE-2018-1000084

5.4MEDIUM

Key Information:

Vendor

Wolfcms

Status
Vendor
CVE Published:
13 March 2018

What is CVE-2018-1000084?

WolfCMS version 0.8.3.1 is susceptible to a Stored Cross-Site Scripting vulnerability, specifically within the Layout Name field in the Layout tab. A low privilege user could exploit this issue by inputting malicious JavaScript code into the Layout Name, potentially allowing them to steal cookies from an admin user and compromise the admin account. This can lead to unauthorized access and control over the website, highlighting significant security risks for users of this CMS.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.