Stored XSS Vulnerability in WUZHI CMS by WUZHI
CVE-2018-11549

5.4MEDIUM

Key Information:

Vendor

Wuzhicms

Status
Vendor
CVE Published:
29 May 2018

What is CVE-2018-11549?

A stored cross-site scripting (XSS) vulnerability has been identified in WUZHI CMS version 4.1.0. This security issue arises in the 'Account Settings -> Member Centre -> Chinese Information -> Ordinary Member' section, where maliciously crafted QQ numbers can be injected via form submissions. This flaw allows attackers to store and execute arbitrary scripts in the user's browser, potentially compromising sensitive user information and overall system integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.