Cross-Site Scripting Vulnerability in WolfCMS from WolfCMS
CVE-2018-15842

4.8MEDIUM

Key Information:

Vendor

Wolfcms

Status
Vendor
CVE Published:
25 August 2018

What is CVE-2018-15842?

WolfCMS version 0.8.3.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the 'slug' parameter in the admin page's URL. This issue can lead to potential unauthorized actions and data theft by exploiting user sessions. Users are encouraged to implement appropriate security measures and consider updating to more secure versions.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.