Stored XSS Vulnerability in WUZHI CMS 4.1.0 Product by WUZHI
CVE-2018-17426

5.4MEDIUM

Key Information:

Vendor

Wuzhicms

Status
Vendor
CVE Published:
7 March 2019

What is CVE-2018-17426?

WUZHI CMS version 4.1.0 contains a stored XSS vulnerability that allows an attacker to inject malicious scripts through the 'Extension module' in the 'SMS in station' field under the index.php?m=core URI. This security flaw poses a serious risk to web applications using this CMS by enabling unauthorized actions and potentially compromising user data.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.