Cross-Site Scripting Vulnerability in EasyCMS by Team Easy
CVE-2018-10374
6.1MEDIUM
What is CVE-2018-10374?
EasyCMS version 1.3 is susceptible to a Cross-Site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts via the 's' POST parameter in the search functionality. Specifically, a crafted request to index.php?s=/index/search/index.html could exploit this flaw, potentially compromising user data and session integrity. Proper input validation and sanitization measures are essential to mitigate such vulnerabilities.
