Cross-Site Scripting Vulnerability in Wolf CMS by Wolf CMS
CVE-2018-14837

4.8MEDIUM

Key Information:

Vendor

Wolfcms

Status
Vendor
CVE Published:
10 August 2018

What is CVE-2018-14837?

Wolf CMS version 0.8.3.1 is susceptible to a cross-site scripting vulnerability within the Snippets tab. This flaw can be exploited through specially crafted URIs, such as ?/admin/snippet/edit/1, allowing malicious users to execute arbitrary scripts in the context of a victim's browser. As a result, it poses a risk of session hijacking, data theft, and other malicious activities. It is crucial for users and administrators to apply necessary patches and updates to mitigate this security issue.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.