Stored XSS Vulnerability in WUZHI CMS 4.1.0 Product by WUZHI
CVE-2018-17426
5.4MEDIUM
What is CVE-2018-17426?
WUZHI CMS version 4.1.0 contains a stored XSS vulnerability that allows an attacker to inject malicious scripts through the 'Extension module' in the 'SMS in station' field under the index.php?m=core URI. This security flaw poses a serious risk to web applications using this CMS by enabling unauthorized actions and potentially compromising user data.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
