Stored XSS Vulnerability in WUZHI CMS by WUZHI
CVE-2018-11549
5.4MEDIUM
What is CVE-2018-11549?
A stored cross-site scripting (XSS) vulnerability has been identified in WUZHI CMS version 4.1.0. This security issue arises in the 'Account Settings -> Member Centre -> Chinese Information -> Ordinary Member' section, where maliciously crafted QQ numbers can be injected via form submissions. This flaw allows attackers to store and execute arbitrary scripts in the user's browser, potentially compromising sensitive user information and overall system integrity.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability Reserved
Vulnerability published
